Snort monitoring of spanning interface
Posted
by
aHunter
on Server Fault
See other posts from Server Fault
or by aHunter
Published on 2010-12-16T02:11:44Z
Indexed on
2010/12/22
16:56 UTC
Read the original article
Hit count: 205
I have configured a Cisco 3500 switch with a port SPAN and have my snort node (fedora 13) plugged into it. I am running snort as a daemon and have configured a rule to log all tcp traffic but I am only seeing traffic with a destination of the snort node. I know that the SPAN port is working and wanted to know if there is a specific option that I needed to start snort with in order for it to pickup all the traffic? Or is there something that I have missed here?
Many thanks.
© Server Fault or respective owner