[Snort-users] recommendation for monitoring traffic

John Friedman jfriedmanx at ...131...
Thu Oct 27 08:03:26 EDT 2005


Hi all,
 
Curently, I span the firewall  port  on teh core switch to the snort monitoring port only  for Rx traffic.  The snort is placed inside firewall.I manage it through the second NIC on the Snort box.   Should I monitor both TX/Rx traffic?  
 
If I want to exclude one server from the monitoring segment, what's the syntax?
 
Thanks in advance,
 
John
 
 
 
BTW, I tried to exclude on server from this motoring segment 

		
---------------------------------
 Yahoo! FareChase - Search multiple travel sites in one click.  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20051027/e0ee802b/attachment.html>


More information about the Snort-users mailing list