Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Problem while capturing Data in SNORT

Hi,

We have a 3550 catalyst working as a core switch. All the VLAN traffic passes through this switch. The IP Range for default VLAN and VLANs are different.

We have configured SNORT (2.6.0) on a linux machine. The SNORT is working, It is capturing the traffic from default VLAN only. As the traffic coming from other VLANs are contacting core switch and then comes to the snort interface the SNORT logs all the traffic from VLANS on the core switch's IP.

Is there any way to log the VLANs traffic on the individual IP address basis?

180
Views
0
Helpful
0
Replies
CreatePlease to create content