Yup that's the right location!

A passive tap (US$500 or make 'em yourself from the instructions at
snort.org) on the trunk works great...

I wonder, however, if a bridge requires handling VLAN tags.

-----Burton 

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of
Rivalino Matias Jr.
Sent: Friday, August 05, 2005 12:29 PM
To: [email protected]
Subject: RE: [Ntop] VLANs and NTOP

Diego,

I think Burton said ntop need be located in a place where it can see the
VLAN tags, like on the trunk (e.g. switch to switch layer 1 connection). It
is possible, for example, running ntop in a linux bridge box. In this case
you can put the box (ntop+linux bridging) between two switches.

Rivalino.

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Diego
de Oliveira
Sent: Friday, August 05, 2005 11:48 AM
To: [email protected]
Subject: Re: [Ntop] VLANs and NTOP


Thanks Burton,

    Really, You're be right. I´m going to find a NIC that support 802.1Q,
because today I don't have one.

best Regards

----- Original Message -----
From: "Burton Strauss" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Friday, August 05, 2005 12:04 AM
Subject: RE: [Ntop] VLANs and NTOP


> Depends on your LAN setup.  If ntop sees the tags (say it's tapping a 
> trunk), then it reports them.  If it doesn't see the VLAN tagged 
> packets, it won't (can't) report them.
>
> -----Burton
>
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf 
> Of Willy, Andrew
> Sent: Thursday, August 04, 2005 4:29 PM
> To: '[email protected]'
> Subject: RE: [Ntop] VLANs and NTOP
>
> VLAN tags are stripped before they're sent to the host aren't they?
>
> Andrew
>
> -----Original Message-----
> From: Diego de Oliveira [mailto:[EMAIL PROTECTED]
> Sent: Thursday, August 04, 2005 12:01 PM
> To: [email protected]
> Subject: [Ntop] VLANs and NTOP
>
>
> HI Folks !
> Does Anyone know , how can I configure the Ntop tool for shown me 
> vlans tag?
> is it possible?
>
>
> Regards,
>
> _______________________________________________
> Ntop mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop
> NOTICE OF CONFIDENTIALITY-The information in this email, including 
> attachments, may be confidential and/or privileged and may contain 
> confidential health information. This email is intended to be reviewed 
> only by the individual or organization named as addressee. If you have 
> received this email in error please notify Scottsdale Medical Imaging, 
> an affiliate of Southwest Diagnostic Imaging, LTD immediately - by 
> return message to the sender or to [EMAIL PROTECTED] - and destroy all 
> copies of this message and any attachments. Please note that any views 
> or opinions presented in this email are solely those of the author and 
> do not necessarily represent those of Scottsdale Medical Imaging. 
> Confidential health information is protected by state and federal law, 
> including, but not limited to, the Health Insurance Portability and 
> Accountability Act of 1996 and related regulations.
> _______________________________________________
> Ntop mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop
>
> _______________________________________________
> Ntop mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop
>
> Esta mensagem foi verificada pelo E-mail Protegido Terra.
> Scan engine: McAfee VirusScan / Atualizado em 04/08/2005 / Versão:
> 4.4.00/4550
> Proteja o seu e-mail Terra: http://mail.terra.com.br/
>

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop


_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop

Reply via email to