<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNORT and mirroring port? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snort-and-mirroring-port/m-p/475432#M1057034</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. You need to figure out what ports contain the traffic you want to view, and also how much data that might be. I knew that a fast ethernet port connecting to a PIX would contain all the data entering and exiting our network, so that is the port I mirrored for snort to monitor. I was mostly interested in monitoring the traffic entering and exiting our network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure how well snort deals with vlan tags - you might need to ensure that snort is only getting non tagged packets. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Sep 2005 15:30:04 GMT</pubDate>
    <dc:creator>mostiguy</dc:creator>
    <dc:date>2005-09-09T15:30:04Z</dc:date>
    <item>
      <title>SNORT and mirroring port?</title>
      <link>https://community.cisco.com/t5/network-security/snort-and-mirroring-port/m-p/475431#M1057015</link>
      <description>&lt;P&gt;I have a 4507R switch with multiple VLANS or subnets. I've installed SNORT on a test machine I have but it doesn't pick up anything outside of it's subnet. According to the documentation I read I won't be able to see all the traffic on the switch and need to mirror a port. Anyone with experience using SNORT with a switched network?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort-and-mirroring-port/m-p/475431#M1057015</guid>
      <dc:creator>kendalle01</dc:creator>
      <dc:date>2020-02-21T08:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: SNORT and mirroring port?</title>
      <link>https://community.cisco.com/t5/network-security/snort-and-mirroring-port/m-p/475432#M1057034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. You need to figure out what ports contain the traffic you want to view, and also how much data that might be. I knew that a fast ethernet port connecting to a PIX would contain all the data entering and exiting our network, so that is the port I mirrored for snort to monitor. I was mostly interested in monitoring the traffic entering and exiting our network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure how well snort deals with vlan tags - you might need to ensure that snort is only getting non tagged packets. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2005 15:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort-and-mirroring-port/m-p/475432#M1057034</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2005-09-09T15:30:04Z</dc:date>
    </item>
  </channel>
</rss>

