Antwort: [nsp] 6509 & Snort

Nelson Novaes Neto nelson.novaes at e-financial.com.br
Thu Feb 26 12:40:24 EST 2004



VACL works fine...

http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/sw_8_2/confg
_gd/acc_list.htm#1020508

[]s
Nelson Novaes.


> -----Original Message-----
> From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-
> bounces at puck.nether.net] On Behalf Of Hans-Peter Walter HAWA
> Sent: quarta-feira, 25 de fevereiro de 2004 10:39
> To: cisco-nsp at puck.nether.net
> Subject: Antwort: [nsp] 6509 & Snort
>
> Hi,
> try using "set span ..."
>
> Have fun,
> HP
>
>
> cat> (enable) show span
>
> Destination     : Port 2/21
> Admin Source    : Port 2/4
> Oper Source     : None
> Direction       : transmit/receive
> Incoming Packets: disabled
> Learning        : enabled
> Filter          : -
> Status          : inactive
>
>
------------------------------------------------------------------------
> Total local span sessions:  1
>
>
>
> cat> (enable) set span ?
>   disable                    Disable port monitoring
>   <mod/port>                 Source module and port numbers
>   <vlan>                     Source VLAN numbers
>
> cat> (enable) set span 2/4 2/21 ?
>   both                       Both receiving and transmitting traffic
>   create                     Creating new SPAN session
>   filter                     Monitor traffic on selected vlans
>   inpkts                     Enable/disable destination port incoming
> packets
>   learning                   Enable/disable MAC address learning
>   rx                         Receiving traffic
>   tx                         Transmitting traffic
>   <cr>
>
>
>
>
>
>
>
> "Rieman, Jeff" <j-rieman at onu.edu>
> Gesendet von: cisco-nsp-bounces at puck.nether.net
> 25.02.2004 14:34
>
>         An:     <cisco-nsp at puck.nether.net>
>         Kopie:
>         Thema:  [nsp] 6509 & Snort
>
>
> I am experiencing with snort and a 6509.  The documentation shows
where
> the snort server should sit between 2 routers to capture all the
traffic
> that passes between them.  I would like to capture all the traffic
that
> goes through the 6509.  Is there a way to put a 10/100 port in a mode
> where it forwards all the packets to that port also?
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
>
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/

________________________________________
Esta mensagem e seus anexos podem conter informacoes confidenciais ou privilegiadas, se voce nao e o destinatario dos mesmos e nao esta
autorizado a utilizar este material para qualquer fim, solicitamos que voce apague a mensagem e avise imediatamente ao remetente. O conteudo desta
mensagem e seus anexos nao representam necessariamente a opiniao e a intencao da empresa, nao implicando em qualquer obrigacao ou
responsabilidade por parte da mesma.
This message may contain confidential and/or privileged information, if you are not the addressee or not authorized to receive this message for any
purpose, please advise the sender immediately by reply e-mail and delete this message. The contents of this message and its attachments do not
necessarily express the opinion or the intention of the company, and do not imply any legal obligation or responsibilities from this company.
________________________________________



More information about the cisco-nsp mailing list