Re: Snort and Cisco Pix

From: Drew - Home (simonis@myself.com)
Date: 10/25/01


Message-ID: <01cd01c15d72$7c93a3f0$c9d8bfa8@DD9SW5MNNNH9TY>
From: "Drew - Home" <simonis@myself.com>
To: <focus-ids@securityfocus.com>
Subject: Re: Snort and Cisco Pix
Date: Thu, 25 Oct 2001 09:31:22 -0700


----- Original Message -----
From: "Greg Shipley" <gshipley@neohapsis.com>

> >
> > Are you sure about this ? The Cisco salesperson told us it was running
> > Linux, not NT.
>
> The Cisco sales person is wrong. It's NT, unless Cisco totally changed it
> recently.
>

Also, it is important to note that the packet capture is all done within the
context of a hardware accelerator. NT can't capture traffic very well, as
we probably all know, so all of those functions are accomplished on
dedicated hardware. There is no interaction with the NT stack.



Relevant Pages

  • RE: CISCO IDS Packet capture
    ... The Cisco Secure Intrusion Detection Sensor runs on a modified ... Stopping cids turns off the intrusion detection function of the sensor. ... Subject: CISCO IDS Packet capture ...
    (Focus-IDS)
  • RE: CISCO IDS Packet capture
    ... > Subject: CISCO IDS Packet capture ... > Does anyone know how to enable some level of packet capture and logging on ... The feature you're referring to is known as "IP Logging" in Cisco's ...
    (Focus-IDS)
  • Re: CISCO IDS Packet capture
    ... For each signature on a newer Cisco sensor, you have the ability to turn on ... > Does anyone know how to enable some level of packet capture and logging on ... > the CISCO IDS system (the newer version which interfaces with CiscoWorks ...
    (Focus-IDS)
  • GRE & Policy Routing
    ... the GRE with Cisco and Linux and I found ... For my test I'm using a cisco router with the ... I want to create a GRE tunnel from the Cisco router to ... Internet Protocol, Src Addr: 200.210.11.130 ...
    (comp.dcom.sys.cisco)
  • Re: Routing Back in LINUX!! Help Please!!!
    ... > the GRE with Cisco and Linux and I found ... > I want to create a GRE tunnel from the Cisco router to ...
    (comp.os.linux.networking)