[Snort-users] To hub or not to hub

Bob Staaf rstaaf at ...7930...
Tue Jan 7 07:05:02 EST 2003


Sorry, I came into this thread late :)  Are you replacing the switch with a
hub or adding a hub before your switch?  If you replace the switch with a
hub you are losing a bit of security that a switched network provides.  If
you are adding a hub before your switch you are just adding an extra point
of failure and another piece of equipment to maintain.  I would highly
suggest a tap as the good ones will fail in the open position still allowing
traffic to flow.

There is a good FAQ on the subject at
http://www.robertgraham.com/pubs/sniffing-faq.html

Hope this helps!

Bob Staaf
Southern Web Services
Central, SC

----- Original Message -----
From: "Anthony Scott" <ascott at ...6076...>
To: <snort-users at lists.sourceforge.net>
Sent: Tuesday, January 07, 2003 8:59 AM
Subject: Re: [Snort-users] To hub or not to hub


First, thanks to all for the answers...
The main reason I didn't want to Span the ports is that I don't know how to
do it, or if there would be any consequences on doing so. We use 3Com
3300's, I'll check the documentation.
The hub seemed the easiest... but I read conflicting information.
Thanks again

anthony  scott,
workstation administrator



-------------------------------------------------------
This SF.NET email is sponsored by:
SourceForge Enterprise Edition + IBM + LinuxWorld =omething 2 See!
http://www.vasoftware.com
_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=ort-users






More information about the Snort-users mailing list