Snort mailing list archives

RE: FAQ 10/100 Hubs Block Other Speed Traffic


From: Erek Adams <erek () theadamsfamily net>
Date: Wed, 8 Aug 2001 13:06:19 -0700 (PDT)

On Thu, 9 Aug 2001, Franki wrote:

if you have a dual speed hub, and machines running both speeds (netcards
with 10 and 100),

would it get around that if you had to nic in the snort machine on the
network? one for 10 and one for 100?

Well...  If the hub does it's magic, you'll only see 100mb traffic with the
100mb card and 10mb traffic with the 10mb card.  You would have to be able to
correlate the events for both segments.  It's not the easiest thing to do, but
it might be a workable solution.  I don't like running multiple snort procs.
It's harder to maintain and analyze, IMHO.

I just heard this and I am wondering if its something I need to worry about
before rollin out snort...

Yes.  You do need to worry.  :)

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: