OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: IDS on switch with multiple VLANs
From: Michael Young (mikeUTOPIA2.COM)
Date: Wed Nov 01 2000 - 18:13:51 CST


I'm currently faced with the problem of implementing an IDS in an
environment where multiple VLANs from different subnets exist on a single
switch. Spanning port technology won't help, as you can only have 1
spanning port per switch, so only one VLAN gets the IDS. I've considered
agent-based network IDS, but wonder if the cost per host becomes
prohibitive at around 17,000 machines.

Is there a simple solution I'm missing?