Snort mailing list archives
ISL trunked traffic
From: "Consolvo, Corbett" <ConsolvC () email cofc edu>
Date: Tue, 12 Feb 2002 08:11:03 -0500
Hello I've been running a distributed snort setup for a year now (great stuff!) and all is well, except now I'm moving into parts of my network that have Cisco ISL vlans, which by itself is ok, but I'm trying to find a way to watch trunked ports. As far as I can tell, this means stripping off the ISL headers, which I don't know how to do. Any suggestions? I've seen some talk about it in the past, but I didn't see any solutions (although I may have them, I'm like that sometimes...) Thanks, Corbett
Current thread:
- ISL trunked traffic Consolvo, Corbett (Feb 12)
- <Possible follow-ups>
- FW: ISL trunked traffic Consolvo, Corbett (Feb 12)