User:Mhavela: Difference between revisions

From Alpine Linux
(Moved notes on HSDPA to separate page)
No edit summary
Line 1: Line 1:
= Monitor traffic using Snort and bridged nics =
== Mirrors ==
== Prepare ==
{{mirrors}}
=== Hardware ===
Hardware used in this example:
* Computer with 1 nic
* Switch that handles vlan
* A computer that would be analyzed
=== Setup analyzer/snort box ===
Sets up standard settings - But '''''skip''''' nic-settings
setup-alpine
Sets up and start webconf
setup-webconf
Install needed packages
apk_add bridge-utils
apk_add acf-snort
Because we will use vlan's in this example, we need to install vlan support
modprobe 8021q


=== Switch setup ===
== Releases ==
We need to configure vlans on the ports
Even numbered releases (eg, 1.6.x) are believed to be stable and ready for use in production environments.<BR>
* Port X = Untagged=vlan1
Odd numbered releases (eg, 1.7.x) are development releases. They should be used for testing, learning, and development only.
* Port Y = Untagged=vlan1, Tagged=vlan2
* Port Z = Untagged=vlan2
Attach equipment into each port
* Port X = Gateway for the 'infected' box
* Port Y = Analyzer/Snort box
* Port Z = The 'infected' box


== Configure ==
Minor number increments (for example, from 1.8.2 to 1.8.3) will be bug fixes and security updates only.<BR>
Configure bridge. /etc/conf.d/bridge would look like this:
Minor number increments in development versions (eg, 1.7.0 to 1.7.1) may break things, be warned!
BRIDGES="br0=eth0+eth0.2"
 
Add vlan2 to nic
=== Alpine 1.8 (stable) ===
vconfig add eth0 2
{|
In our case we have a dhcp running on the system, so we configure br0 to get a lease (edit /etc/network/interfaces file)
!
auto br0
! HTTP&nbsp;&nbsp;&nbsp;
iface br0 inet dhcp
! HTTP&nbsp;&nbsp;&nbsp;
Start bridge
! FTP&nbsp;&nbsp;&nbsp;&nbsp;
/etc/init.d/bridge start
! FTP&nbsp;&nbsp;&nbsp;&nbsp;
Bring up bridge
|-
ifup br0
|dl-3.alpinelinux.org
Start snort
|[http://dl-3.alpinelinux.org/alpine/v1.8/iso ISO]
/etc/init.d/snort start
|[http://dl-3.alpinelinux.org/alpine/v1.8/usbdrive USB]
| -
| -
|-
|distrib-coffee.ipsl.jussieu.fr
|[http://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.8/iso ISO]
|[http://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.8/usbdrive USB]
|[ftp://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.8/iso ISO]
|[ftp://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.8/usbdrive USB]
|}
 
 
=== Alpine 1.7 (development) ===
{|
!
! HTTP&nbsp;&nbsp;&nbsp;
! HTTP&nbsp;&nbsp;&nbsp;
! FTP&nbsp;&nbsp;&nbsp;&nbsp;
! FTP&nbsp;&nbsp;&nbsp;&nbsp;
|-
|-
|dl-3.alpinelinux.org
|[http://dl-3.alpinelinux.org/alpine/v1.7/iso ISO]
|[http://dl-3.alpinelinux.org/alpine/v1.7/usbdrive USB]
| -
| -
|-
|distrib-coffee.ipsl.jussieu.fr
|[http://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.7/iso ISO]
|[http://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.7/usbdrive USB]
|[ftp://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.7/iso ISO]
|[ftp://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.7/usbdrive USB]
|}
 
 
=== Alpine 1.6 (stable) ===
{|
!
! HTTP&nbsp;&nbsp;&nbsp;
! HTTP&nbsp;&nbsp;&nbsp;
! FTP&nbsp;&nbsp;&nbsp;&nbsp;
! FTP&nbsp;&nbsp;&nbsp;&nbsp;
|-
|distrib-coffee.ipsl.jussieu.fr
|[http://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.6/iso ISO]
|[http://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.6/usbdrive USB]
|[ftp://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.6/iso ISO]
|[ftp://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine/v1.6/usbdrive USB]
|}
 
 
== Old Releases ==
Old releases can be found on the main [ftp://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine ftp] or
[http://distrib-coffee.ipsl.jussieu.fr/pub/linux/alpine/alpine http] mirror.

Revision as of 15:48, 9 February 2009

Mirrors

Releases

Even numbered releases (eg, 1.6.x) are believed to be stable and ready for use in production environments.
Odd numbered releases (eg, 1.7.x) are development releases. They should be used for testing, learning, and development only.

Minor number increments (for example, from 1.8.2 to 1.8.3) will be bug fixes and security updates only.
Minor number increments in development versions (eg, 1.7.0 to 1.7.1) may break things, be warned!

Alpine 1.8 (stable)

HTTP    HTTP    FTP     FTP    
dl-3.alpinelinux.org ISO USB - -
distrib-coffee.ipsl.jussieu.fr ISO USB ISO USB


Alpine 1.7 (development)

HTTP    HTTP    FTP     FTP    
dl-3.alpinelinux.org ISO USB - -
distrib-coffee.ipsl.jussieu.fr ISO USB ISO USB


Alpine 1.6 (stable)

HTTP    HTTP    FTP     FTP    
distrib-coffee.ipsl.jussieu.fr ISO USB ISO USB


Old Releases

Old releases can be found on the main ftp or http mirror.