[Snort-users] VLAN- Tagged/Untagged and Snort rules

amn0p at ...14399... amn0p at ...14399...
Thu Oct 4 10:32:09 EDT 2012


Hi everyone,

I was doing some reading on this topic but wasnt able to find conclusive answer. How does Snort handle traffic coming from mirrored port on network switch which is mix of vlan tagged and untagged traffic. Due to this would Snort signatures fail or give false positives? If yes, what is the best way to handle, so that Snort works as intended. Thanks for your time and help.
-Amit
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20121004/a9198e7f/attachment.html>


More information about the Snort-users mailing list