[Snort-users] FW: ISL trunked traffic

Consolvo, Corbett ConsolvC at ...4953...
Tue Feb 12 05:33:15 EST 2002

Hello all,
I've been running a distributed snort setup for a year now (great stuff!)
and all is well, except now I'm moving into parts of my network that have
Cisco ISL vlans, which by itself is ok, but I'm trying to find a way to
watch trunked ports.  As far as I can tell, this means stripping off the ISL
headers, which I don't know how to do.  Any suggestions?  I've seen some
talk about it in the past, but I didn't see any solutions (although I may
have them, I'm like that sometimes...)
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20020212/bb608ed2/attachment.html>

More information about the Snort-users mailing list