cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
432
Views
0
Helpful
1
Replies

VACL vs SPAN

jason.andrews
Level 1
Level 1

Based on your experiences, which do you prefer? SPAN seems to expose alot of false positive traffic, but will VACL not expose enough?

1 Reply 1

ishah
Level 1
Level 1

Span will capture everything but is simple

VACLs allow granular control to certain types of traffic can be filtered out by only using capture on the traffic that you are interested in. Care should be taken with your filters otherwise you could be ignoring genunine attacks.

It is better to run IDS on span for some weeks prior to tuning your VACLs to establish what you what to capture and what to ignore. This applies even if using span ports.

IDS does require tuning but one that has been done, it works really well with either technique.