Super Easy Firewall and Gateway System from Untangle

Standard

untangle-logo

Untangle delivers an integrated family of applications that simplify and consolidate the network and security products that businesses need at the network gateway. All Untangle apps are:

  • Pre-configured to work right away
  • Downloadable for rapid deployment
  • Guaranteed to be integrated and run seamlessly on the Untangle Gateway Platform Continue reading

IPS and IDS Tools for Network Admin

Standard

1. Snort IPS – http://www.snort.org/
Snort® is an open source network intrusion prevention and detection system (IDS/IPS) developed by Sourcefire. Combining the benefits of signature, protocol and anomaly-based inspection, Snort is the most widely deployed IDS/IPS technology worldwide. With millions of downloads and over 250,000 registered users, Snort has become the de facto standard for IPS.

2. Sguil – http://sguil.sourceforge.net
Sguil (pronounced sgweel) is built by network security analysts for network security analysts. Sguil’s main component is an intuitive GUI that provides access to realtime events, session data, and raw packet captures.

3. SQueRT – http://squert.sourceforge.net/
SQueRT was created to make most of the data from Sguil accessible via a web browser. While most analysts shun the idea of this, it is especially useful for some people (management, techs) that do not require the real-time event handling and analytical aspects (complexity) of the TCL/TK Sguil client. SQueRT is simply meant to provide a quick overview for non-analysts so that they can address certain obvious problem areas; for example policy violations.

4. SnoGE – http://leonward.wordpress.com/snoge/
Snoge is a Snort unified reporting tool, it processes your unified files (that’s Snort’s output format), and represents them as place-marks on Google Earth. It can operate in a few modes, Real-time, refresh, and one-time.