Skip to content

Opening book details…

About this document

Snort Configuration and Testing on Ubuntu by Robo Shout is a document available to read on EtoBox.

James Colley completed Lab 6 using two machines on his network. He installed Snort on the server at 192.168.0.18 and used the client at 192.168.0.2 to generate traffic. After configuring Snort, he tested it by having the client ping the server, which successfully generated alerts. Next, he uncommented SNMP rules and had the client run Nmap, which Snort correctly identified as a port scan. Finally, he wrote a local rule to detect ping floods from different IP addresses.

Author
Robo Shout
Language
EN