TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

Vincent
FYI:  A gotcha with the tap is that you cannot run kills, as it a one way
communication.
Also, if you put the hub upstream from the switch, you would miss any
communication that is switched on the switch bus but never goes upstream.
(Cannot see some in-house hacks, though you would see the traffic in and out
of the switch).

Using a port with spanning configured would do the trick.
Kirk
-----Original Message-----
From: Bridge, Jim [mailto:[EMAIL PROTECTED]]
Sent: Thursday, February 17, 2000 10:39 AM
To: '???'
Cc: '[EMAIL PROTECTED]'
Subject: RE: switching hub problem



TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any
problems!
----------------------------------------------------------------------------

Vincent,
 
Real Secure must be attached to a mirrored port only, or into a hub placed
BEFORE the switch powering the segment to run Intrusion Detection.
 
My folks tell me that the hub-to-switch scenario will unplug any
full-duplexing running between the switch and anything upstream (toward the
backbone) from it.
 
Shomiti taps are also a solution, but you cannot run RS in Stealth mode in
this case.
 
Jim Bridge

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, February 15, 2000 6:11 PM
To: [EMAIL PROTECTED]
Subject: Fw: switching hub problem


 
------i(c)l?l�Do-----
��H�DoaI: ?A?�P�DI < [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>
>
|?�DoaI: [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>  <
[EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> >
?e��A: 2000|~2?e15?e PM 09:13
�DD|(r): switching hub problem


I had web server, news server, firewall server, router, mail server
connecting to  a sitching hub 
Web server , firewall machine connected to 100 mb port in switching hub
others connected to 10mb port
I decide to place a real secure engine here to detect any activity in this
segment
I use a NT to install real secure engine that is connected to a 10mb port in
switching hub
 
But I can't see any packet (ex. http) from web server in real secure view
Somebody told me real secure cannot detect packet crossing switching hub 
any one had any idea about this?
 
INTERNET
   /
router (10 mb)    
  |              switching  hub
  |              |   |    |      |
|-------------------------------------Real Secure(10mb)
  -----------|   |    



Reply via email to