TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------
Vincent,
Real Secure must be attached to a mirrored port only, or into a hub placed
BEFORE the switch powering the segment to run Intrusion Detection.
My folks tell me that the hub-to-switch scenario will unplug any
full-duplexing running between the switch and anything upstream (toward the
backbone) from it.
Shomiti taps are also a solution, but you cannot run RS in Stealth mode in
this case.
Jim Bridge
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, February 15, 2000 6:11 PM
To: [EMAIL PROTECTED]
Subject: Fw: switching hub problem
------i(c)l?l�Do-----
��H�DoaI: ?A?�P�DI < [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>
>
|?�DoaI: [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> <
[EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> >
?e��A: 2000|~2?e15?e PM 09:13
�DD|(r): switching hub problem
I had web server, news server, firewall server, router, mail server
connecting to a sitching hub
Web server , firewall machine connected to 100 mb port in switching hub
others connected to 10mb port
I decide to place a real secure engine here to detect any activity in this
segment
I use a NT to install real secure engine that is connected to a 10mb port in
switching hub
But I can't see any packet (ex. http) from web server in real secure view
Somebody told me real secure cannot detect packet crossing switching hub
any one had any idea about this?
INTERNET
/
router (10 mb)
| switching hub
| | | | |
|-------------------------------------Real Secure(10mb)
-----------| |