Snort mailing list archives

Re: About to setup snort


From: James Edwards <hackerwacker () cybermesa com>
Date: Thu, 20 May 2004 23:24:38 -0600

On Thu, 2004-05-20 at 14:57, Shaun T. Erickson wrote:
Our networks are small, and with a small number of servers and clients. 
Until such a time as we can afford switches that support a monitoring 
port, we are replacing our 100Mb switches with 100Mb hubs, so that we 
can get access to all the traffic.

Well, yuck. Test this. Once a local host gets an infection
that makes a lot of traffic you will see why this is a bad idea.

james

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: