Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Users
[Top] [All Lists]

RE: [Snort-users] Advice on quad ethernet card

Subject: RE: [Snort-users] Advice on quad ethernet card
Date: Fri, 19 Nov 2004 15:36:58 -0500

I don't think this is a good idea.  You will see a lot of drops if you have
any amount of traffic at all.  If you simply must have this on one box, then
get two dual-ethernet cards, and make sure they are each on a different
internal bus, and put the two lightest trafficced networks on the same card.
That might help.

With a potential of about ~210Mbps (3*70), you shouldn't need a super-fast
disk subsystem at ~25MBps (210Mbps/8) written, but you should make it SCSI
in order to reduce CPU utilization.  The 3 network connections will take up
some cpu, snort itself will take up a bit, and if you use a large ruleset
you could be swamped (IOs for each of the cards and the disks).

I take it the 4'th nic is going to be used to send data to your remote mysql
server....  This could be the straw that breaks the camel's back.

It will be interesting to see how well this works!

--Patrick Darden
--snort, ids, cisco, unix
--linux, firewalls, security


-----Original Message-----
From: Patrick Marquetecken [mailto:patrick.marquetecken@pandora.be]
Sent: Friday, November 19, 2004 4:16 PM
To: Snort
Subject: [Snort-users] Advice on quad ethernet card


Hi,

At my work they are thinking of replacing 3 snort machines by one with a
quad Ethernet card, witch will sniff 3 different lan's.
The network is only 100Mbit, will there not a lot of dropped packages this
way, and they must all send there data with barnyard to a remote mysql
server.
Is it also possible to see in the Database from witch sensor the data is
from? 

TIA
Patrick

-- 
"Please, Spock, do me a favor ... 'n' don't say it's `fascinating'..."
"No... but it is... interesting..." -- Spock

Fingerprint = 2792 057F C445 9486 F932 3AEA D3A3 1B0C 1059 273B
ICQ# 316932703 
Registered Linux User #44550
http://counter.li.org



-------------------------------------------------------
This SF.Net email is sponsored by: InterSystems CACHE
FREE OODBMS DOWNLOAD - A multidimensional database that combines
robust object and relational technologies, making it a perfect match
for Java, C++,COM, XML, ODBC and JDBC. www.intersystems.com/match8
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

<Prev in Thread] Current Thread [Next in Thread>