02-24-2004 11:28 AM - edited 03-02-2019 01:49 PM
Hello, I want to install an IDS solution that needs to have access to all traffic on the LAN. All of my machines plug directly into a 3550 catalyst switch running IOS Version 12.1(13)EA1a.
Is there any way to have a copy of all data sent to a spicific port on the switch (almost like a mirror port). Sorry I am not sure what the appropriate terminology is.
Thanks a lot
Jeff
02-24-2004 12:51 PM
Its called port monitoring for IOS based switches. Below you can find a guide for configuring SPAN on a 3550 switch.
02-25-2004 09:59 AM
The thing to remember is that once a switchport is in destination span mode it won't forward normal traffic. ie you'll need two physical nics plugged into different switchports for a IDS box. Either that or just access the IDS box via console only.
More secure but a pain.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide