monitoring a /21 for potential bad guys with snort and port mirroring

Posted by Adeodatus on Server Fault See other posts from Server Fault or by Adeodatus
Published on 2011-01-14T05:56:29Z Indexed on 2011/01/14 6:55 UTC
Read the original article Hit count: 530

Hi all,

I want/need to start monitoring our network a bit better. Its an odd network in that it comprises 2 /22 public IPs and a slew of private admin IPs. I do have one point in the network where it all comes together and I can turn on port mirroring on the catalyst. From that port, I'd like to turn up a box running various utilities. Snort is high on my list but it'd be nice to also get some networking statistics with something like Netflow.

So, what are peoeple's thoughts. I can turn up a box needed for this with a bit of ease. We have the hardware available. What should I run? I'd love to know what kind of nasty things are potentially going on but I'd also like to see statistics on what people are doing on the network so I can better tweak our systems to handle it better and improve performance.

I'm open so please, give me some ideas to go along with what I've got.

© Server Fault or respective owner

Related posts about linux

Related posts about networking