cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
198
Views
0
Helpful
1
Replies

New ids 4210

kwonza
Level 1
Level 1

In the process of putting a 4210 online. Updated sp's and sig updates on CSPM and appliance, all went well. Woud like to run a baseline for 2 weeks to view and monitor type of traffic accessing main 3500 series switch which main servers ( email, web, fileservers, etc...), are connected to. All are behind pix firewall. So I connected promicious 4210 port into 3500 switch. Do I need to configure the port for port mirroring for all ports connected to servers in order to monitor data to the servers.

1 Reply 1

travis-dennis_2
Level 7
Level 7

You would need to configure SPAN so that the IDSs port can watch all the traffic that hits the switch.

http://www.cisco.com/en/US/customer/products/hw/switches/ps646/products_configuration_guide_chapter09186a008007f3d5.html