Snort monitoring of spanning interface

Posted by aHunter on Server Fault See other posts from Server Fault or by aHunter
Published on 2010-12-16T02:11:44Z Indexed on 2010/12/22 16:56 UTC
Read the original article Hit count: 186

Filed under:
|
|

I have configured a Cisco 3500 switch with a port SPAN and have my snort node (fedora 13) plugged into it. I am running snort as a daemon and have configured a rule to log all tcp traffic but I am only seeing traffic with a destination of the snort node. I know that the SPAN port is working and wanted to know if there is a specific option that I needed to start snort with in order for it to pickup all the traffic? Or is there something that I have missed here?

Many thanks.

© Server Fault or respective owner

Related posts about linux

Related posts about snort