Intrusion Detection Systems mailing list archives

RE: RE: IDS taps in a switched network


From: blaing () iss net (Brian Laing)
Date: Mon, 1 Nov 1999 14:20:53 -0000



Thing to keep in mind is that the 12 port device from shomiti can only
monitor one port at a time.  It is build so their network sniffer can talk
to the 12 port tap and tell the tap which of the 12 ports it would like to
listen to.

Brian

I agree that the 12-Tap is an effective way to monitor 12 ports at a time.
But many enterprise switches (and virtually all boxes for ISPs and
carriers)
have many more than 12 ports. In my opinion it's better to have
hardware-based monitoring built right into the switch.



Current thread: