<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Did you enable &amp;quot;Promiscuous in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-mirroring-issue/m-p/3023270#M43029</link>
    <description>&lt;P&gt;Did you enable "&lt;SPAN&gt;Promiscuous Mode&lt;/SPAN&gt;" on your vSwitch?&lt;/P&gt;
&lt;P&gt;https://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1004099&lt;/P&gt;</description>
    <pubDate>Wed, 29 Mar 2017 08:16:07 GMT</pubDate>
    <dc:creator>Dennis Perto</dc:creator>
    <dc:date>2017-03-29T08:16:07Z</dc:date>
    <item>
      <title>IDS MIRRORING ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/ids-mirroring-issue/m-p/3023269#M43028</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I have a below doubt on my setup. I am not sure whether setup i have built is as per IDS standards or not but SNORT IDS is not capturing traffic. I want to be sure from switch end i have mapped the needs of IDS. Below is the setup i have built.&lt;/P&gt;
&lt;P&gt;Step1:&lt;/P&gt;
&lt;P&gt;Built EIGRP between router &amp;amp; switch over checkpoint transparent firewall. Neighourship/Routes are received as expected.&lt;/P&gt;
&lt;P&gt;Router4431---Gi0/0/1Routed Port(IP- 10.10.10.10/29)---------(L2 Bridge)Checkpoint(L2Bridge)---------Gig 0/0/1Routed Port(10.10.10.9/29)3850.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Step2:&lt;/P&gt;
&lt;P&gt;Created Snort on VM Dell Server on Shared NIC(VSwitch Group2) with IP 10.10.5.19. NIC is connected to 3850 L2 port Gi0/0/2. This IP is reachable from network working as expected. Other VMs are also reachable under this Vswitch Group. Snort Service on VM is active &amp;amp; running.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Step3:&lt;/P&gt;
&lt;P&gt;Need is to monitor the traffic on Inside interface on 3850switch ie Gi0/0/1 which is routed to capture traffic which is received &amp;amp; transfered over this inside port.&lt;/P&gt;
&lt;P&gt;I have used a port on Dell Server on separate NIC which is placed under dedicated for Snort mirror port Vswitch Group3 connected to 3850 L2 port Gi0/0/3. IP not assigned to this port. Switch port configuration for mirroring is as below.&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface gi0/0/1---Connected to Dell Server Shared Vswitch NIC 2 for all VMS&lt;/P&gt;
&lt;P&gt;no shut&lt;/P&gt;
&lt;P&gt;no switchport&lt;/P&gt;
&lt;P&gt;ip add 10.10.10.9 255.255.255.248&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface gi0/0/1---Connected to Dell Server Shared Vswitch NIC 2 for all VMS&lt;/P&gt;
&lt;P&gt;no shut&lt;/P&gt;
&lt;P&gt;switchport access vlan 2201--VLAN for VM Servers including SNORT&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface gi0/0/3---Connected to Dell Server dedicated Vswitch NIC 3 for Snort Mirroring&lt;/P&gt;
&lt;P&gt;no shut&lt;/P&gt;
&lt;P&gt;switchport mode access&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;monitor session 2 source interface Gi0/0/1 both&lt;/P&gt;
&lt;P&gt;monitor session 2 destination interface Gi0/0/3.&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;Is above setup is correct? I am not getting logs in snort, i think i am missing something. Please highlight your thoughts on this, can we monitor routed port as a source &amp;amp; Mirror port on Snort side will work without IP?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Vishal&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:48:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-mirroring-issue/m-p/3023269#M43028</guid>
      <dc:creator>Vishal Kolamkar</dc:creator>
      <dc:date>2019-03-10T13:48:10Z</dc:date>
    </item>
    <item>
      <title>Did you enable "Promiscuous</title>
      <link>https://community.cisco.com/t5/network-security/ids-mirroring-issue/m-p/3023270#M43029</link>
      <description>&lt;P&gt;Did you enable "&lt;SPAN&gt;Promiscuous Mode&lt;/SPAN&gt;" on your vSwitch?&lt;/P&gt;
&lt;P&gt;https://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1004099&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 08:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-mirroring-issue/m-p/3023270#M43029</guid>
      <dc:creator>Dennis Perto</dc:creator>
      <dc:date>2017-03-29T08:16:07Z</dc:date>
    </item>
  </channel>
</rss>

