cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
364
Views
0
Helpful
1
Replies

Monitor or Span port Vulnerablility

sagittarius
Level 1
Level 1

Is the CISCO IDS/IPS device connecting to Monitor or SPAN port Vulnerable? Is there a document which I can refer to ?

1 Reply 1

mhellman
Level 7
Level 7

It's very unlikely, but not impossible. Snort's had a few and the general concept is applicable to any IDS. If you suck in data off the network and process it, there's the potential for vulnerabilities. If you're worried about it, put the management interface in a management dmz.

http://www.infoworld.com/article/03/03/04/HNsnort_1.html

Review Cisco Networking products for a $25 gift card