Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: [Snort-users] Advice on quad ethernet card |
|---|---|
| Date: | Fri, 19 Nov 2004 15:36:58 -0500 |
I don't think this is a good idea. You will see a lot of drops if you have any amount of traffic at all. If you simply must have this on one box, then get two dual-ethernet cards, and make sure they are each on a different internal bus, and put the two lightest trafficced networks on the same card. That might help. With a potential of about ~210Mbps (3*70), you shouldn't need a super-fast disk subsystem at ~25MBps (210Mbps/8) written, but you should make it SCSI in order to reduce CPU utilization. The 3 network connections will take up some cpu, snort itself will take up a bit, and if you use a large ruleset you could be swamped (IOs for each of the cards and the disks). I take it the 4'th nic is going to be used to send data to your remote mysql server.... This could be the straw that breaks the camel's back. It will be interesting to see how well this works! --Patrick Darden --snort, ids, cisco, unix --linux, firewalls, security -----Original Message----- From: Patrick Marquetecken [mailto:patrick.marquetecken@pandora.be] Sent: Friday, November 19, 2004 4:16 PM To: Snort Subject: [Snort-users] Advice on quad ethernet card Hi, At my work they are thinking of replacing 3 snort machines by one with a quad Ethernet card, witch will sniff 3 different lan's. The network is only 100Mbit, will there not a lot of dropped packages this way, and they must all send there data with barnyard to a remote mysql server. Is it also possible to see in the Database from witch sensor the data is from? TIA Patrick -- "Please, Spock, do me a favor ... 'n' don't say it's `fascinating'..." "No... but it is... interesting..." -- Spock Fingerprint = 2792 057F C445 9486 F932 3AEA D3A3 1B0C 1059 273B ICQ# 316932703 Registered Linux User #44550 http://counter.li.org ------------------------------------------------------- This SF.Net email is sponsored by: InterSystems CACHE FREE OODBMS DOWNLOAD - A multidimensional database that combines robust object and relational technologies, making it a perfect match for Java, C++,COM, XML, ODBC and JDBC. www.intersystems.com/match8 _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-users] Call for Papers: Bellua Cyber Security Asia 2005, Anthony.zboralski |
|---|---|
| Next by Date: | RE: [Snort-users] Found true hub, Richard Bejtlich |
| Previous by Thread: | Re: [Snort-users] Advice on quad ethernet card, sekure |
| Next by Thread: | RE: [Snort-users] Advice on quad ethernet card, Richard Bejtlich |
| Indexes: | [Date] [Thread] [Top] [All Lists] |