Snort mailing list archives

Ethernet Tap vs Span Port


From: <Victor.Correia () international gc ca>
Date: Tue, 11 Jan 2005 09:14:40 -0500

Hi All,
 
I'm currently in the process of implementing Snort. I was wondering
witch of the TAP or Span port was best route to go.
 
For the TAP I'm looking at these 2: Critical TAP System NCT3C1 and Net
Optics 96443 - 10/100 Port Aggregator Tap
 
Does any of you used one of those? Are they good?
 
For the spanning port, I was thinking of monitoring the gateway port
from my core switch to the firewall. I'm a bit concern about spanning
port, since the switch must duplicate all the incoming and outgoing
traffic of the switch, could that cause the switch to fail? the switch I
want to use for that is a Cisco 2950.
 
Which of these option is the best one to implement Snort on a network to
monitor only the LAN.
 
Thank for your input.
 
Vic

Current thread: