[Snort-users] Cisco Catalyst - SNORT

Falvo, Jose Luis - (Arg) Jose.Falvo at ...3247...
Mon Jun 23 08:19:08 EDT 2003


Thanks Javier,
Could will be any performance problem configuring SPAN port in a switch with
high traffic ?
Regards,
jose


-----Mensaje original-----
De: Javier Liendo [mailto:javier at ...7920...]
Enviado el: Lunes, 23 de Junio de 2003 11:56 a.m.
Para: Falvo, Jose Luis - (Arg); 'Snort-users at lists.sourceforge.net'
Asunto: Re: [Snort-users] Cisco Catalyst - SNORT


hello jose

you'll have to configure the switch port where you are
plugging the snort device as a "span" port...

pls take a look at the following link to see how you
can configure it on a 6000 series catalyst switch...

http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/12_1e/swconfig/s
pan.htm

also in my experience, if you configure a switch port
as span then you can not pass any management traffic
through that port so you will have to add another
network card and plug it to another switch port if you
want to manage this device remotely...

saludos

javier


--- "Falvo, Jose Luis - (Arg)" <Jose.Falvo at ...3247...>
wrote:
> Hi All,
> I'm probing Snort in our network. Snort was
> installed and its run correctly.
> Our problem is that snort only listen packet unicast
> to snort IP or any
> broadcast packet of VLAN where its was connected. 
> Questions is:
> 
> In a Cisco Catalyst 8540 or Calalyst 6509, which is
> configuration port for
> SNORT listen all packet of the VLAN?
> 
> Regards and thanks,
> 
> 
> Jose Luis Falvo
> Dpto. Ingeniería 
> AT&T Latin America
> Tel. (54 11) 5288-0182 
>  Olga Cosentini  1031 - Cap Fed
>                                                   
> Buenos Aires - Argentina
> 
> Este mensaje es confidencial. El mismo contiene
> información reservada 
> y que no puede ser difundida. Si usted ha recibido
> este e-mail 
> por error, por favor avísenos inmediatamente vía
> e-mail y tenga la 
> amabilidad de eliminarlo de su sistema; no deberá
> copiar el mensaje 
> ni divulgar su contenido a ninguna persona. Muchas
> gracias.
>  
> This message is confidential. It contains
> information that is privileged and
> legally exempt from disclosure. If you have received
> this e-mail by mistake,
> 
> please let us know immediately by e-mail and delete
> it from your system; 
> you should also not copy the message nor disclose
> its contents to anyone. 
> Thank You.
> 
> 
> 
>
-------------------------------------------------------
> This SF.Net email is sponsored by: INetU
> Attention Web Developers & Consultants: Become An
> INetU Hosting Partner.
> Refer Dedicated Servers. We Manage Them. You Get 10%
> Monthly Commission!
> INetU Dedicated Managed Hosting
> http://www.inetu.net/partner/index.php
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or
> unsubscribe:
>
https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
>
http://www.geocrawler.com/redir-sf.php3?list=snort-users
Este mensaje es confidencial. El mismo contiene información reservada 
y que no puede ser difundida. Si usted ha recibido este e-mail 
por error, por favor avísenos inmediatamente vía e-mail y tenga la 
amabilidad de eliminarlo de su sistema; no deberá copiar el mensaje 
ni divulgar su contenido a ninguna persona. Muchas gracias.
 
This message is confidential. It contains information that is privileged and
legally exempt from disclosure. If you have received this e-mail by mistake,

please let us know immediately by e-mail and delete it from your system; 
you should also not copy the message nor disclose its contents to anyone. 
Thank You.





More information about the Snort-users mailing list