Question on Snort based IDS

Discussion in 'other firewalls' started by Kees1958, Dec 10, 2009.

Thread Status:
Not open for further replies.
  1. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Recently some Windows PC options are available for stand alone PC's (Bothunter). What is the opinion of the FireWall experts on this.

    Does it makes sense to guard some PC's of family members through this IDS in combination with an inbound Router Nat/SPI firewall. I do not want a lock tight outbound firewall, since it will not be used in the correct manner, still I would like some info on the PC's network activity.

    Thanks Kees
     
  2. red_dolphin

    red_dolphin Registered Member

    Joined:
    Oct 19, 2009
    Posts:
    9
    Bothunter is a good heuristic diagnostic solution.

    Bothunter does not protect your PC but alerts you in case of suspicious traffic.

    But you still need some expertise to read the logs.
     
  3. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Red (?) Delphin,

    Thanks. Yes I understand it is an intrusion detection system. Just figuring out how I can be warned by e-mail, when it discovers something on other PC's.

    Have not found a way yet.

    Regards Kees
     
  4. red_dolphin

    red_dolphin Registered Member

    Joined:
    Oct 19, 2009
    Posts:
    9
    I have snort and prelude already installed on my server so I tried bothunter one year ago.

    I found it good but redundant.

    You should post your question on the official forum. they are quite reactive.
     
Loading...
Similar Threads
  1. ttomm1946
    Replies:
    0
    Views:
    521
Thread Status:
Not open for further replies.