Skip to main content

Posts

Showing posts from April, 2018

Snort as NIDS. Installation and configuration Step by Step.

Install Required Dependencies ############################# apt-get update -y apt-get upgrade -y apt-get install openssh-server ethtool build-essential libpcap-dev libpcre3-dev libdumbnet-dev bison flex zlib1g-dev liblzma-dev openssl libssl-dev wget https://www.snort.org/downloads/snort/daq-2.0.6.tar.gz tar -zxvf daq-2.0.6.tar.gz cd cd daq-2.0.6 ./configure && make && make install Install Snort from Source: ########################## wget https://www.snort.org/downloads/snort/snort-2.9.11.1.tar.gz tar -xvzf snort-2.9.11.1.tar.gz cd snort-2.9.11.1 ./configure --enable-sourcefire && make && make install ldconfig ln -s /usr/local/bin/snort /usr/sbin/snort snort -V Configure Snort ############### mkdir /etc/snort mkdir /etc/snort/preproc_rules mkdir /etc/snort/rules mkdir /var/log/snort mkdir /usr/local/lib/snort_dynamicrules touch /etc/snort/rules/white_list.rules touch /etc/snort/rules/black_list.rules touch