cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
454
Views
3
Helpful
1
Replies

SPAN port or Capture?

zoot.admin
Level 1
Level 1

We currently have Cat6513 switches installed and our looking into an IDSM-2 module, but for the time being until we can actually purchase them, I would like to install a few snort sensor into the switch to "monitor" a few VLANs.

I've read where there are only two SPAN ports and to gain some type of correlation to the events, I figure I would need to install a separate snort sensor for each vlan. The problem is the limit of two SPAN ports. I heard that there is a way to utilize a "capture" feature on the 65xx systems.

Is the appropriate way for this to use the "capture" commands and if so how would I do that?

Also, I read where the SPAN ports have no performance impact on the switch, but would the "capture" commands?

I apologize if this is the wrong forum for this but I wasn't sure if this would be more of a switching or IDS question...

Thanks for any assistance!

-Jeff

1 Reply 1

john.stark
Level 1
Level 1

The solution to that issue of only two span ports is to use VACLS. There is documentation in the Configuring the Cisco Intrusion Prevention System Sensor Using the Command Line Interface 5.1.

http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_guide_chapter09186a008055df92.html#wp1030828

Refer to Catalyst 6500 Series Switch Command Reference for more information on trunk ports and ACLs.

Review Cisco Networking products for a $25 gift card