Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-users] Snort on two load-balanced links (using SPAN on a Cisco 6500) |
|---|---|
| Date: | Wed, 27 Apr 2005 08:56:38 -0600 |
I am considering using Snort to monitor two uplinks on a Cisco 6500 into the core. This will be done using SPAN to mirror the traffic on both uplinks to single port. Assume that bandwidth is not a problem. These are equal-cost routes, so traffic will be load-balanced by OSPF. (I think this is load-balanced by flow, not per packet). Does anyone know what the effect this setup (load-balanced links) will have on the ability of Snort to do it's job? Tristan Rhodes ------------------------------------------------------- SF.Net email is sponsored by: Tell us your software development plans! Take this survey and enter to win a one-year sub to SourceForge.net Plus IDC's 2005 look-ahead and a copy of this survey Click here to start! http://www.idcswdc.com/cgi-bin/survey?id=105hix _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-users] adding another sensor, Jason Benway |
|---|---|
| Next by Date: | Re: [Snort-users] Fedora Core Linux 3 -- Snort IDS, Alejandro Flores |
| Previous by Thread: | [Snort-users] Fedora Core Linux 3 -- Snort IDS, Pradeep Aswani |
| Next by Thread: | [Snort-users] permissions denied error for alert log on new snort install, Jason Benway |
| Indexes: | [Date] [Thread] [Top] [All Lists] |