Snort mailing list archives

RE: How does snort handle 802.1Q VLAN tag packets?


From: "Willy, Andrew" <AWilly () eSMIL net>
Date: Wed, 9 Feb 2005 15:26:05 -0700

VLAN tags are stripped before being sent to the host access port.  Or are
you monitoring a trunk port?  Even still, the VLAN aware NIC you must have
installed in your Snort machine removes the tags before passing them up ...

I think.

Andrew



-----Original Message-----
From: Nyuk Loong Kiw [mailto:Kiw () safecom co nz]
Sent: Wednesday, February 09, 2005 3:15 PM
To: snort-users () lists sourceforge net
Subject: [Snort-users] How does snort handle 802.1Q VLAN tag packets?


Hi all,

Sorry for a newbie Q.

Just finish reading a snort book and have got a play box up and running
at home. Would like to know how does snort handle packets' that are VLAN
tag? Will snort still be able to decode them properly??

Thanks


Kiw
############################################################################
#########
Important: This electronic message and attachments (if any) are confidential
and may be legally privileged. If you are not the intended recipient do not
copy, disclose or use the contents in any way. Please let us know by return
e-mail immediately and then destroy this message.
############################################################################
#########


-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_ide95&alloc_id396&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
NOTICE OF CONFIDENTIALITY-The information in this email, including
attachments, may be confidential and/or privileged and may contain
confidential health information. This email is intended to be reviewed only
by the individual or organization named as addressee. If you have received
this email in error please notify Scottsdale Medical Imaging, an affiliate
of Southwest Diagnostic Imaging, LTD immediately - by return message to the
sender or to support () esmil com - and destroy all copies of this message and
any attachments. Please note that any views or opinions presented in this
email are solely those of the author and do not necessarily represent those
of Scottsdale Medical Imaging. Confidential health information is protected
by state and federal law, including, but not limited to, the Health
Insurance Portability and Accountability Act of 1996 and related
regulations.


-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: