logo
bgImage
http://www.winsnort.com


Welcome to the home of WinIDS - Windows Intrusion Detection System!
header

Thank you for visiting WINSNORT.com


Post new topic   Reply to topic
View previous topic Printable version Log in to check your private messages View next topic
Author Message
rjclark2Offline
Post subject: Master/Slave Communications via openssh  PostPosted: Apr 17, 2008 - 07:16 AM



Joined: Apr 17, 2008

Posts: 4

Status: Offline
Has anyone gotten a slave win-ids system talking to a master win-ids system using ssh tunnels? I configured a putty session to tunnel port 3306 to the master system and on the slave I configure snort.conf to update the database using localhost via port 3306. I'm not seeing any alerts showing up on my base console even though I granted access to my slave's real addresse on the master's mysql DB.
 
 View user's profile Send private message  
Reply with quote Back to top
MorpheusOffline
Post subject: RE: Master/Slave Communications via openssh  PostPosted: Apr 17, 2008 - 11:34 AM
Site Admin


Joined: Sep 04, 2003
East Coast - USA
Posts: 1415
Location: East Coast - USA
Status: Offline
Are you able to manually connect to the mysql server from the slave?

_________________
Best regards,
Morpheus...

WINSNORT.com Management
 
 View user's profile Send private message Visit poster's website MSN Messenger  
Reply with quote Back to top
rjclark2Offline
Post subject: RE: Master/Slave Communications via openssh  PostPosted: Apr 19, 2008 - 04:10 AM



Joined: Apr 17, 2008

Posts: 4

Status: Offline
The two systems are separated by a firewall so, no I haven't actually gotten the two to communicate with each other, but the slave did work with another master that resided on the same subnet as the slave. I moved the master to a new system and updated the various config files accordingly(at least I thought I did). I guess my next step will be to move this new master to the slave's subnet for a quick verification test and see what happens. At least this will prove to me that the two can communicate with each and my problem is really with ssh. Having said this though, do you know if anyone has a master/slave topology working using openssh? Thanks for your reply. I'll let you know how I make out. Regards.
 
 View user's profile Send private message  
Reply with quote Back to top
MorpheusOffline
Post subject: RE: Master/Slave Communications via openssh  PostPosted: Apr 20, 2008 - 02:39 AM
Site Admin


Joined: Sep 04, 2003
East Coast - USA
Posts: 1415
Location: East Coast - USA
Status: Offline
Ok, thanks.

_________________
Best regards,
Morpheus...

WINSNORT.com Management
 
 View user's profile Send private message Visit poster's website MSN Messenger  
Reply with quote Back to top
rjclark2Offline
Post subject: RE: Master/Slave Communications via openssh  PostPosted: Apr 23, 2008 - 11:01 AM



Joined: Apr 17, 2008

Posts: 4

Status: Offline
Well, I figured out my problem. The slave was talking to the master the whole time but I had the switch port configured for only tx traffic and I had commented out one of the Iicmp rules. it just so happened that once I reconfigured the switch for rx traffic and uncommented the icmp rule, the alerts started to flow. Thank you for letting me bounce this problem off of you.
 
 View user's profile Send private message  
Reply with quote Back to top
MorpheusOffline
Post subject: RE: Master/Slave Communications via openssh  PostPosted: Apr 23, 2008 - 03:27 PM
Site Admin


Joined: Sep 04, 2003
East Coast - USA
Posts: 1415
Location: East Coast - USA
Status: Offline
NP, glad you got it working.

_________________
Best regards,
Morpheus...

WINSNORT.com Management
 
 View user's profile Send private message Visit poster's website MSN Messenger  
Reply with quote Back to top
Display posts from previous:     
Jump to:  
All times are GMT -5 Hours
Post new topic   Reply to topic
View previous topic Printable version Log in to check your private messages View next topic

Powered by PNphpBB2 © 2003-2009. The PNphpBB2 Team
www.eventloganalyzer.com