03-21-2003 12:58 PM - edited 03-09-2019 02:36 AM
Hod do I configure my CSPM to use my IDS as a sniffer. Is there a beginner's configuration guide on CSPM for IDS management. I have IDS and CSPM installed and tlaking oto each other,
03-24-2003 03:23 AM
I think you cant.
Use NAM for it.
Br
Rolands
03-24-2003 05:56 AM
Can you tell me how to use NAM to do so? We already have NAM installed and running fine but we are not using it much.
03-26-2003 12:23 AM
04-08-2003 02:31 AM
i think basic of a sniffer and a IDS is quite the same ,
but i geuss IDS is much more costomized for special use such is signiture triggers .
are u looking for some fun ?
have a search over " offensive use of IDS ", big corporation are spending money towards finind a solution to map networks located far from each others.
04-25-2003 01:52 PM
Yes, it can be done. Here is a link detailing how to do this.
The sniff can be triggered on a signature alert. The sniff will miss the first packet in the conversation, but you can still view this packet in the event viewer. I believe future versions of the IDS software will re-insert that first packet back into the sniff.
04-28-2003 04:57 AM
I have been through the link. But , I dont have the " PACKET CAPTURE DEVICE" selection option on my screen. Here are the versions of CSPM and IDS:
Sensor version is : 3.0(1)S4
CSPM version is : 2.3.3i
Please comment.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide