Snort mailing list archives

RE: Snort on an 802.1q link


From: Christopher Lyon <cslyon () netsvcs com>
Date: Fri, 25 Oct 2002 17:18:03 -0700

So there is no configuration needed? Snort will read pass the tagging and
just go right to the layer 3 information?


-----Original Message-----
From: Jason [mailto:security () brvenik com] 
Sent: Friday, October 25, 2002 5:16 PM
To: Christopher Lyon
Cc: 'snort-users () lists sourceforge net'
Subject: Re: [Snort-users] Snort on an 802.1q link

It should just work, I've tested it before but ended up not using it.

Christopher Lyon wrote:

Hi all,
I have a campus environment with uplinks to remote switches that are 
using 802.1q tagging. There are a bunch of VLANs that are going over 
these links so I want to be able to look at all the traffic. Is there 
a configuration on Snort or the OS platform that needs to be done in 
order to read the information going over these links? I am using RH 8.0.





Current thread: