Snort mailing list archives

Re: Snort on span port


From: "Michael J. Pelletier" <mjpelletier () mjpelletier com>
Date: Wed, 11 Aug 2004 16:09:25 -0700

Hello

The Cisco 5500 series switches have a bad rep for dropping packets on SPAN
ports. Unfortunetly, if everything is corretly configured and you still are
dropping packets you might try putting the IDS on a hub with the other links.
This would eliminate the need for a SPAM port. Understand this is not the best
way to do things but, it does get arround the 5500s problem with SPAM ports.

Take Care,
Michael


/*******************************************/
UNIX is a very friendly OS. It is just picky
about who it makes friends with.
/*******************************************/

Disclaimer:
This electronic message, including any attachments, is confidential and intended solely for use of the intended 
recipient(s). This message may contain information that is privileged or otherwise protected from disclosure by 
applicable law. Any unauthorized disclosure, dissemination, use or reproduction is strictly prohibited. If you have 
received this message in error, please delete it and notify the sender immediately.


-------------------------------------------------------
SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media
100pk Sonic DVD-R 4x for only $29 -100pk Sonic DVD+R for only $33
Save 50% off Retail on Ink & Toner - Free Shipping and Free Gift.
http://www.shop4tech.com/z/Inkjet_Cartridges/9_108_r285
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: