NIDS Recommendations in limited environment...
From: Clint Byrum (cbyrum@spamaps.org)Date: 07/31/02
- Previous message: kaleal: "RE: Okena StormWatch"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Clint Byrum <cbyrum@spamaps.org> To: focus-ids@securityfocus.com Date: 31 Jul 2002 13:31:32 -0700
Ok, after running into the mostly useless Intel 510 "port mirroring" in
quite a few locations, I need some advice. What does one do when the
switch in use, cannot provide proper monitoring functions.
Most of the time I'm dealing with a relatively small amount of traffic,
on the order of 30-40Mbit at absolute peak times, and an average of
0.5-1Mbit. The HP ProCurve switches seem to handle this just fine with
their monitoring port setup.
I am using snort on midrange x86 boxes running Linux in most cases.
Thanks in advance.
- Previous message: kaleal: "RE: Okena StormWatch"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|