Snort mailing list archives
RE: Snort on an 802.1q link
From: Christopher Lyon <cslyon () netsvcs com>
Date: Fri, 25 Oct 2002 17:18:03 -0700
So there is no configuration needed? Snort will read pass the tagging and just go right to the layer 3 information? -----Original Message----- From: Jason [mailto:security () brvenik com] Sent: Friday, October 25, 2002 5:16 PM To: Christopher Lyon Cc: 'snort-users () lists sourceforge net' Subject: Re: [Snort-users] Snort on an 802.1q link It should just work, I've tested it before but ended up not using it. Christopher Lyon wrote:
Hi all, I have a campus environment with uplinks to remote switches that are using 802.1q tagging. There are a bunch of VLANs that are going over these links so I want to be able to look at all the traffic. Is there a configuration on Snort or the OS platform that needs to be done in order to read the information going over these links? I am using RH 8.0.
Current thread:
- Snort on an 802.1q link Christopher Lyon (Oct 25)
- Re: Snort on an 802.1q link Jason (Oct 25)
- <Possible follow-ups>
- RE: Snort on an 802.1q link Christopher Lyon (Oct 25)