回覆 1# xpking
如果要用wireshark/snort/suricata之類的network sniffer/intrusion detection system,raspberry pi可能唔多夠力,另外個network switch要有port mirror功能。仲有https traffic因為encrypt咗都係睇唔到內容,最多只係sniff到dns query。既然係睇dns query,不如用隻raspberry pi起個pi hole dns server,可以log低所有dns query,又可以block埋啲廣告/malware website。 |