34 Network Monitoring – Snort Network IDS/IPS
Julian Romano and Jacob Christensen
This chapter will guide learners to install and configure Snort as an Intrusion Detection System (IDS) and an Intrusion Prevention System (IPS) for their enterprise network. Many companies may spend upward of tens of thousands of dollars on IDS and IPS devices for their security needs. Luckily for us, Snort is free to use and experiment with.
Learning Objectives
- Install the Snort Package into the pfSense Server
- Configure Snort to be an effective IDS and IPS
- Trigger alerts to test Snort rules against threats
Prerequisites
Deliverables
4 screenshots are needed to earn credit for this exercise:
- Screenshot of GNS3 Working environment once everything works
- Screenshot of the pfSense GUI page after sign in
- Screenshot of alert notifications through snort
Resources
- Special thanks to
Contributors and Testers
- Jacob M. Christensen, Cybersecurity Student, ERAU-Prescott
- Zeek Correa, Cybersecurity Student, ERAU-Prescott
- Jungsoo Noh, Cybersecurity Student, ERAU-Prescott
Phase I – Setting up the Lab
The following steps are to create a baseline environment for completing the lab. It makes assumptions about learner knowledge from completing previous labs.
This lab is an extension of Chapter 31:
- Open GNS3
- Open the lab made in Chapter 31
- Save it as a new project: LAB_19
- Set up GNS3 as shown in the network diagram above
NOTE: This example uses version 2.7.2 of pfSense Community Edition.
- Start and login to the PC on the Management LAN
- Open a browser and type in https://<IP_ADDRESS>/ to connect to the pfSense web configuration page
NOTE: Remember to use the default creds to login:
– Username: admin
– Password: pfsense
- Open a browser and type in https://<IP_ADDRESS>/ to connect to the pfSense web configuration page
- In the pfSense GUI, navigate to System–>Package Manager to install Snort
- Click on Available Packages, search for “snort”
NOTE: If you are having trouble getting this to work, ensure that pfSense is fully updated (System–>Update) and that its WAN interface (ISP) is receiving a DHCP address from the NAT cloud.
- Click Install and Confirm to begin the Snort installation process
- Once completed, you should now see Snort listed under the Installed Packages tab
- Click on Available Packages, search for “snort”
Phase II – Enable and Configure Snort in pfSense
In this section we will setup Snort and configure the rules needed to make our IDS effective.
- Navigate to Services-->Snort
- Select the Global Settings tab and enable the download of various pre-configured rulesets (Figure 5)
- Click on Enable Snort VRT is selected
- Enter the Snort Oinkmaster Code associated with your snort.org account
NOTE: If you do not have a snort account, click Sign Up for a free Registered User Rules Account. You may not have internet on your VM, so you can go here on your host machine. Once taken to the sign up page, provide an email and password for your free snort