LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-04-2005, 05:57 PM   #1
Dogit
Member
 
Registered: Feb 2005
Distribution: Suse 9.0,9.2 Pro
Posts: 67

Rep: Reputation: 15
Smile iptables & snort


Hello,To all

Ok now that i have snort installed should i
also install iptables do i need it

great weekend to all

Thank you
 
Old 03-04-2005, 06:32 PM   #2
gr33ndata
Member
 
Registered: Aug 2003
Location: DMZ
Distribution: Ubuntu
Posts: 144

Rep: Reputation: 15
It depends
Snort is a signature based IDS (Intrusion Detection System), while IPTables is a Firewall.
An IDS alerts you in case there is an attack (it has some limited blocking like tcp reset or so). And a firewall is used to permit or block the access to some ip's, ports, protocls etc.
As a rule of thunmb you need a cascaded security solution with a firewall as the first layer of defence succeeded by an IDS (IDP).
Also see the following link for more information:
http://www.juniper.net/solutions/lit.../fw_idp_wp.pdf

Last edited by gr33ndata; 03-04-2005 at 06:37 PM.
 
Old 03-04-2005, 06:35 PM   #3
Gibsonist
Member
 
Registered: Mar 2004
Location: Meersburg (GER)
Distribution: Cygwin,RH 7.2 7.3, SuSe 6.4 8.2 9.1,TinyLinux, Debian Sarge, Knoppix 3.*, Knoppicilin, Knoppix STD
Posts: 191

Rep: Reputation: 30
Well, I find it hard to phrase it, but here goes

snort is only a IDS (intrusion DETECTION system)
opposed by iptables which are a firewall - meant to keep out people

I personally would install iptables as I am a very mistrusting person
and also use iptables to add a second layer of security on my applications

On client installations I often use 2 net tabs before and behind the firewall to have snort show me how well the firewall is and what has been stopped.

I hope this helps

PS there is a thread here about the necessity of a firewall
http://www.linuxquestions.org/questi...threadid=99496

Last edited by Gibsonist; 03-04-2005 at 06:44 PM.
 
Old 03-10-2005, 10:00 AM   #4
havelino
LQ Newbie
 
Registered: Jan 2005
Location: The Netherlands
Distribution: Debian 3.0 Sarge
Posts: 29

Rep: Reputation: 15
If you want to block based on the snort alerts try snortsam
snortsam
 
Old 05-05-2005, 05:02 PM   #5
TheLinuxDuck
Member
 
Registered: Sep 2002
Location: Tulsa, OK
Distribution: Slack, baby!
Posts: 349

Rep: Reputation: 33
Actually, snort is not just an IDS. It also does tcpdump-style packet logging, packet sniffing, IDS, and iptables-inline packet checking. My understanding is that it doesn't interfere with a firewall, if one is running on the system, though not all modes may be friendly with a firewall.. I don't know for certain on that point.

Dogit:

If you want to use inline mode , you'll need iptables setup and running, also ip_queue, which is how iptables passes packets on to snort. I think the most common way to use it is IDS mode, which doesn't require iptables or any other firewall.

The docs over at snort.org are pretty good.
 
Old 06-01-2005, 01:54 PM   #6
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Rep: Reputation: 30
are you putting iptables on the same machine as snort or are you planning on using snort behind a firewall to view attacks that made it through the firewall???

Also just to point it out you can use snort to create firewall rules dynamically when being attacked via iptables, however this can lead to a DOS attack if the attacker knows whats going on and uses it to his advantage, also care must be used becuase false positives could lead you to blocking legit traffic
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Using Snort with iptables,How to dimsh Linux - Security 2 09-24-2005 08:15 AM
Securing System: Snort, IPTables, Logging Matir Linux - Security 1 11-29-2004 03:06 PM
Snort and Iptables Question kemplej Linux - Networking 0 09-15-2004 10:57 AM
Snort, prelude, fwbuilder, bastille or iptables ? christophe.dr Linux - Security 5 10-28-2003 01:59 PM
snort and iptables on same machine cestor Linux - Security 8 06-13-2002 03:32 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:11 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration