Snort mailing list archives

Snort & Cisco Catalyst ISL


From: Dave Cundiff <dave.cundiff () exchange1 cybx net>
Date: Mon, 4 Mar 2002 08:50:08 -0500

I'm looking at setting up snort for my network here but have a quick
question that I can't seem to answer from any of the documentation. I'm
going to be using a hardware sniffer to copy the ISL trunk going between my
main switch and my router to a snort box. This should allow snort to sniff
all traffic on my network. However since it's an ISL trunk all the packets
will have an additional header on them containing what vlan the packet is
for.

So my question is can or is there some way that Snort can ignore that first
header? Or will it just not be able to make any sense out of the packet?

Dave Cundiff
Systems Administrator
World Wide Net, Inc.
http://www.wwnet.net



_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: