cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
648
Views
0
Helpful
2
Replies

Network Forensics monitoring

wilson_1234_2
Level 3
Level 3

I know this is a little off the mark but,

We have some people from Network Forensics installing monitoring equipment soon.

Supposedly, this device is going to capture every packet on the network.

How does this work and will it slow things down?

We have many VLANs, are they going to monitor every default gateway?

How would something like this be done?

2 Replies 2

varakantam
Level 1
Level 1

http://www.cisco.com/en/US/products/sw/cscowork/ps5209/index.html

This should give you some good overview of the product

mhellman
Level 7
Level 7

Do you mean NetForensics? If so, it's a SIM product and it doesn't collect packets...it collects events. IDS events. Router events. Firewall events. Host events. etc, etc. Are you a network guy and the security guys will be using this product? They can impact the network, but not in the way you're thinking. A router configured to log events [maybe that it previously was not configured to] could become overloaded. Devices sending events over a slow link could saturate the link. etc.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: