cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
240
Views
0
Helpful
2
Replies

IDS 4.0 - checking SPAN port

SCOTT MCINTIRE
Level 1
Level 1

In sensor version 3.x, I used to be able to check the monitoring port by using snoop command. I was told by TAC that 'tcpdump' could be used on 4.x version but they couldn't tell me how to get to the proper place to use the command. Anyone know how to use tcpdump on a IDS sensor utilizing version 4.x?

2 Replies 2

ywadhavk
Cisco Employee
Cisco Employee

Hi Scott,

Login to the sensor using the service account, then su to root by entering the command ' su ' without the quotes, cd to /usr/sbin. This directory should have the command tcpdump.

To run this command, at the prompt enter the below;

./tcpdump -i eth0 OR eth1 as the case maybe.

Hope this helps.

yatin

Forgot to add this,

use the same password for the ' su ' as for the service account.

Yatin

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: