Intrusion Detection Systems mailing list archives

Taps


From: STEVEN.LODIN () ROCHE COM (Lodin, Steven {IT 4~Indianapolis})
Date: Wed, 29 Mar 2000 08:28:40 -0500


Sometime in the next couple of months we are changing our Internet/DMZ
architecture from shared 10Mbit to switched 100 Mbit.  I've been watching
the discussion on taps with great interest.

There are at least three vendors:

Shomiti - http://www.shomiti.com
ODS - http://www.ods.com
NetOptics - http://www.netoptics.com

One of the gotchas with a tap, so I've been told, is that they have 4 ports.
Two are dedicated to incoming/outgoing traffic.  The other two are the taps
off that traffic, one for each direction.  Is this true of all taps in
general?  From what I understand, there are two solutions to using one
network detector to watch both incoming and outgoing traffic, pull both
ports into a hub or into a switch.  In theory, a switch should be used
because of CSMA/CD?  In practice, what is being used?

Are there any other gotchas with respect to taps?

Thanks!

Steve


Current thread: