Snort mailing list archives

ISL trunked traffic


From: "Consolvo, Corbett" <ConsolvC () email cofc edu>
Date: Tue, 12 Feb 2002 08:11:03 -0500

Hello
I've been running a distributed snort setup for a year now (great stuff!)
and all is well, except now I'm moving into parts of my network that have
Cisco ISL vlans, which by itself is ok, but I'm trying to find a way to
watch trunked ports.  As far as I can tell, this means stripping off the ISL
headers, which I don't know how to do.  Any suggestions?  I've seen some
talk about it in the past, but I didn't see any solutions (although I may
have them, I'm like that sometimes...)
 
Thanks,
Corbett

Current thread: