|
|||||||||||
|
RE: sniffing packets on a switch
From: Brad Davenport <BDavenport(at)scan-direct.com>
Date: Tue Mar 11 2003 - 13:19:17 EST
IE, your firewall port is spanned to another switchport to allow your IDS to sample all incoming data destined for the trusted net. --BD
-----Original Message-----
Do you know what kind of problems?
The most obvious problem with doing this is that, by
default, your sniffer machine's port on the switch will
only be sent traffic that is either broadcast, or addressed
specifically to the sniffer host.
There *are* ways to try that may make this happen if you don't have administrative access to the switch, and there might even be some tools around that automate such measures. But on most well-run networks, people without admin access to things like switches are also not authorized to be running sniffers, so let's not go there in a public forum.... David Gillett > -----Original Message-----
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:03:53 EDT |
||||||||||
|
|||||||||||