[Snort-users] Snort on span port

Michael J. Pelletier mjpelletier at ...12250...
Wed Aug 11 16:11:00 EDT 2004


The Cisco 5500 series switches have a bad rep for dropping packets on SPAN
ports. Unfortunetly, if everything is corretly configured and you still are
dropping packets you might try putting the IDS on a hub with the other links.
This would eliminate the need for a SPAM port. Understand this is not the best
way to do things but, it does get arround the 5500s problem with SPAM ports.

Take Care,

UNIX is a very friendly OS. It is just picky
about who it makes friends with.

This electronic message, including any attachments, is confidential and intended solely for use of the intended recipient(s). This message may contain information that is privileged or otherwise protected from disclosure by applicable law. Any unauthorized disclosure, dissemination, use or reproduction is strictly prohibited. If you have received this message in error, please delete it and notify the sender immediately.

More information about the Snort-users mailing list