Snort mailing list archives
Snort & Cisco Catalyst ISL
From: Dave Cundiff <dave.cundiff () exchange1 cybx net>
Date: Mon, 4 Mar 2002 08:50:08 -0500
I'm looking at setting up snort for my network here but have a quick question that I can't seem to answer from any of the documentation. I'm going to be using a hardware sniffer to copy the ISL trunk going between my main switch and my router to a snort box. This should allow snort to sniff all traffic on my network. However since it's an ISL trunk all the packets will have an additional header on them containing what vlan the packet is for. So my question is can or is there some way that Snort can ignore that first header? Or will it just not be able to make any sense out of the packet? Dave Cundiff Systems Administrator World Wide Net, Inc. http://www.wwnet.net _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort & Cisco Catalyst ISL Dave Cundiff (Mar 04)