Snort mailing list archives
RE: How does snort handle 802.1Q VLAN tag packets?
From: "Willy, Andrew" <AWilly () eSMIL net>
Date: Wed, 9 Feb 2005 15:26:05 -0700
VLAN tags are stripped before being sent to the host access port. Or are you monitoring a trunk port? Even still, the VLAN aware NIC you must have installed in your Snort machine removes the tags before passing them up ... I think. Andrew -----Original Message----- From: Nyuk Loong Kiw [mailto:Kiw () safecom co nz] Sent: Wednesday, February 09, 2005 3:15 PM To: snort-users () lists sourceforge net Subject: [Snort-users] How does snort handle 802.1Q VLAN tag packets? Hi all, Sorry for a newbie Q. Just finish reading a snort book and have got a play box up and running at home. Would like to know how does snort handle packets' that are VLAN tag? Will snort still be able to decode them properly?? Thanks Kiw ############################################################################ ######### Important: This electronic message and attachments (if any) are confidential and may be legally privileged. If you are not the intended recipient do not copy, disclose or use the contents in any way. Please let us know by return e-mail immediately and then destroy this message. ############################################################################ ######### ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://ads.osdn.com/?ad_ide95&alloc_id396&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users NOTICE OF CONFIDENTIALITY-The information in this email, including attachments, may be confidential and/or privileged and may contain confidential health information. This email is intended to be reviewed only by the individual or organization named as addressee. If you have received this email in error please notify Scottsdale Medical Imaging, an affiliate of Southwest Diagnostic Imaging, LTD immediately - by return message to the sender or to support () esmil com - and destroy all copies of this message and any attachments. Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of Scottsdale Medical Imaging. Confidential health information is protected by state and federal law, including, but not limited to, the Health Insurance Portability and Accountability Act of 1996 and related regulations. ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- How does snort handle 802.1Q VLAN tag packets? Nyuk Loong Kiw (Feb 09)
- RE: How does snort handle 802.1Q VLAN tag packets? Marc Norton (Feb 09)
- Message not available
- Re: How does snort handle 802.1Q VLAN tag packets? Matt Kettler (Feb 09)
- Web based administration N B (Feb 10)
- Re: Web based administration Matt Kettler (Feb 10)
- RE: Web based administration Brian Jameson (Feb 11)
- Re: How does snort handle 802.1Q VLAN tag packets? Matt Kettler (Feb 09)
- RE: How does snort handle 802.1Q VLAN tag packets? Eric Hines (Feb 09)
- <Possible follow-ups>
- RE: How does snort handle 802.1Q VLAN tag packets? Willy, Andrew (Feb 09)