06-03-2021 06:04 PM
Dear Users,
I'm a newbie and I'm trying to analyze the traffic on all the ports of a Cisco switch using Snort.
I know that I can use the port mirroring feature to copy the traffic running on source port to a destination port monitored by Snort. But, if I need to analyze all the switch ports, how can I do the work?
Can I consider the switch uplink port as source port? Or I should do it in a different way?
Thank you in advance,
Mauro
06-04-2021 02:12 AM
- You might use a 'span copy' of the uplink port ,check this document for more info's :
https://www.cisco.com/c/en/us/support/docs/switches/catalyst-6500-series-switches/10570-41.html
M.
06-04-2021 02:15 AM
M.
06-04-2021 04:37 AM
Mirror the traffic of all the ports and send to SNORT, like spanning the session.
06-08-2021 03:42 AM
Sorry for my late answer.
Thank you very much to all of you.
I really appreciated.
Mauro
06-08-2021 04:16 AM
No worries, Hope our information is very helpfull for you, if this was resolve mark as resolution, so other community member can use as reference - if they have same query.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide