Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

IDS for small business

I am looking to setup an IDS for a small business ~30 workstations. I have used open source products in the past such as Snort/Acid/Sguil. I just need to have a port on the router/switch to receive all the packets on a certain network segment. I don't think that i need a $2000 device just to use port monitoring on a switch. Are there any economical product recommendations for a switch or a firewall/vpn with a "monitoring port"?


New Member

Re: IDS for small business

Is there a way to set up a similar setup without wasting a switch to this. We currently run all our traffic through a Cisco 3600 and and then out through the firewall. So is it possible to set a port on the router to do the same as the switch monitoring port or do we have to get a switch in between the router and the firewall.


Re: IDS for small business

If you're looking to get by with the least expense possible, you could use a plain old 10BaseT Broadcast Hub between your router and firewall. I assume that your internet access is DSL speeds or less, so the hub will not be a bottleneck. I havn't seen a good or easy way of using a router to copy traffic.

New Member

Re: IDS for small business

Well the line is a 10Mbit and behind it is about 1500 workstations so I would not stick an old hub out there. But ok thanks you answered the questions. So I'll order a new switch.

The problem is the rackmounts are getting really crowded and the AC in the server room is working very hard during the summer so I was hoping I could avoid throwing another heat source and space taker in there.

Thanks anyway for the fast answer.

CreatePlease to create content