[Snort-users] Snort on switched network
cmorford at ...3733...
Tue Oct 9 11:23:11 EDT 2001
I'm running Snort on a mirrored port on my switched network and it seems to
I don't know why it would be a bad idea.
If your IDS box is attched to a non-mirrored switch port you're not getting
all the traffic, only what's on your segment.
Ashley Thomas wrote:
> It is a bad idea to run Snort (or any IDS for that matter) on a switched
> network, am i right ?
> Are there any work arounds ?
> thanks a lot
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> Snort-users list archive:
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 425 bytes
Desc: Card for Chuck Morford
More information about the Snort-users