I've spent some hours yesterday on this issue. I've installed Entware on a dedicated USB stick (I tried with Optware first as this was already installed, but the snort package there was too old and couldn't find appropriate rules). The installed package "as is" needs several tweaks to configuration to have it run, but integrating and adapting what I found here
http://tomatousb.org/forum/t-369388/step-by-step-procedure-for-installing-and-configuring-snort
I succeeded to do it. However, after everything appeared properly set up, the app would crash right after startup because of low memory (couldn't allocate some memory pool). For this reason I configured a 0.5GB swap file on the USB stick and this everything went "apparently" fine.
Apparently because on-screen messages seems ok, log file seems ok, but I couldn't see any alert. I tried to configure a specific rule to alert on a ping to a specific machine in the network, but without success.
Anyone could shed some light on it ?
Thanks in advance
Peppe
http://tomatousb.org/forum/t-369388/step-by-step-procedure-for-installing-and-configuring-snort
I succeeded to do it. However, after everything appeared properly set up, the app would crash right after startup because of low memory (couldn't allocate some memory pool). For this reason I configured a 0.5GB swap file on the USB stick and this everything went "apparently" fine.
Apparently because on-screen messages seems ok, log file seems ok, but I couldn't see any alert. I tried to configure a specific rule to alert on a ping to a specific machine in the network, but without success.
Anyone could shed some light on it ?
Thanks in advance
Peppe