OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Jonathan G. Lampe (jonathanstdnet.com)
Date: Tue Jun 05 2001 - 10:57:10 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Short Answer: When it's a switch.

    I was trying to set up a SNORT sensor array (multiple SNORT sensors on
    multiple machines hooked up a single hub, uplinked to a hub on the network I
    wanted to monitor), but I quickly noticed none of my SNORT boxes were
    getting any traffic (except broadcast traffic) from the network I wanted to
    monitor. I pulled my brand new LinkSys "hub" off the network and put a
    SNORT box back on Hub#1 - saw all the traffic again.

    ----Hub#1(OK)-----(network I want to monitor)
           |
         LinkSys
       / | \
    SNORT SNORT SNORT

    After some experimentation I found my LinkSys "hub" was really a "switch" -
    it figured out the ethernet addresses of the devices plugged into it and was
    only passing packets to the correct devices - thus thwarting my efforts to
    listen in on the network I wanted to monitor.

    I purchased my brand new LinkSys "Etherfast 5Port 10/100 Auto-Sensing
    'Workgroup' Hub W/5 RJ45 Ports" (UPC 0745883548835) from buy.com for $40 -
    you'd think a cheap hub would be just a dumb repeater, but it wasn't. So
    here's what I'm looking for: (PLEASE EMAIL DIRECTLY TO jonathanstdnet.com)

    Brand/Device names of currently-available "hubs" which...
    ...are dumb repeaters (good for SNORT sensor arrays)
    ...switch (bad for SNORT sensor arrays)
    (Or links to or lists of places who have already compiled this list!)

    If I get a good list of hubs (>10?) together, I'll repost it here, but until
    then, please email any responses directly to jonathanstdnet.com to keep
    this discussion board from filling up with hub chatter...;)

    TIA, Jonathan Lampe, Standard Networks, Inc., jonathanstdnet.com

    _______________________________________________
    Snort-users mailing list
    Snort-userslists.sourceforge.net
    Go to this URL to change user options or unsubscribe:
    http://lists.sourceforge.net/lists/listinfo/snort-users
    Snort-users list archive:
    http://www.geocrawler.com/redir-sf.php3?list=snort-users