Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Capturing NID traffic with CISCO

From: David W. Goodrum <dgoodrum(at)nfr.com>
Date: Fri Nov 08 2002 - 11:53:16 EST

Craig,

Which version of NFR are you running? We are a very stateful IDS, so you are correct, that it's important for us to see both sides of the traffic. Our NID-315 and 320 series come with multiple sniffing interfaces, which should allow you to configure SPAN ports from both sides, and pump that data directly into the NID, allowing us to re-assemble that traffic correctly.

Attached is a .gif file that diagrams this setup.

Of course, if your A and B side are not near eachother, getting the SPAN'ed data to us might be difficult. :)

If you have any more questions, let me know.

-dave

Do you need help?X

"Craig M. Taylor" wrote:
>
> Folks,

-- 
David W. Goodrum
Senior Systems Engineer
NFR Security
Mobile: 703.731.3765
Office: 240.747.3425

320D_Load-Balanced_network.gif
Received on Mon Nov 11 16:07:17 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:04 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library