Back to tutorials
Key takeaways
- Snort is a signature-based network IDS/IPS: it compares live traffic against rule sets. It needs at least two network interfaces, one for management and one dedicated to listening.
- Four things must be checked in
/etc/snort/snort.conf:ipvar HOME_NETmust match your actual local network,ipvar EXTERNAL_NET !$HOME_NET,var RULE_PATH /etc/snort/rules, and theinclude $RULE_PATH/local.rulesline must be uncommented so your own rules get loaded. - Always validate the configuration with
snort -T -c /etc/snort/snort.confbefore launching anything. In detection mode:snort -A console -q -u snort -g snort -c /etc/snort/snort.conf -i eth1, where-inames the monitoring interface and alerts are logged under/var/log/snort. - To validate the whole chain end to end, add a test rule to
/etc/snort/rules/local.rules—alert icmp any any -> $HOME_NET any (msg:"ICMP ping test"; sid:1000001; rev:1;)— then ping the server from another machine on the network: the alert should appear on the console. - IPS (inline) mode is started with
-Q --daq afpacket -i eth0:eth1and requires switching rules fromalerttodroporreject: traffic then physically crosses Snort, and a bad rule cuts legitimate traffic. Suricata, a more modern multi-threaded fork, is often preferred for new high-throughput deployments.
What is Snort?
Snort is an open-source network intrusion detection and prevention system (IDS/IPS). It analyzes network traffic in real time and compares it against a set of rules to identify malicious activity, port scans, vulnerability exploitation attempts, and other threats. It is one of the oldest and most widely recognized IDS tools.
Snort is an open-source network intrusion detection and prevention system (IDS/IPS). It analyzes network traffic in real time and compares it against a set of rules to identify malicious activity, port scans, vulnerability exploitation attempts, and other threats. It is one of the oldest and most widely recognized IDS tools.
Why use Snort?
- Signature-based detection: Very effective at detecting known threats thanks to vast rule sets (official, community, or paid).
- Three operating modes: It can act as a simple packet "sniffer", a packet logger, or a full intrusion detection system.
- Mature and stable: It has decades of development and production use behind it.
- Integration: It can be integrated with other tools (firewalls, SIEM) for automated response.
Prerequisites
- A Linux server (Ubuntu/Debian) with at least two network interfaces: one for management and one for listening (monitoring).
- Root access or sudo privileges.
Premium Content
This advanced tutorial is reserved for premium members.
9,90€ / month
- All advanced tutorials
- New content every week
- Progress tracking
- Cancel anytime