mrbean2766
Programmer
Hello all.
I'm trying to setup a port mirror on a Nortel Baystack 470-24 switch (4 in stack). The purpose of the mirror is so that I can run a IDS on a host other than the firewall itself. So, on the firewall (CentOS 5.10), when I run 'tcpdump -l -nnn -i eth1' (eth1 is the LAN facing interface), I can see all traffic heading to the LAN from the Internet in addition to other noise on the LAN. However, on the IDS, when I run the same tcpdump command as above on the interface designated as the sensor port, I only see local traffic - the traffic destined to internal hosts from the Internet doesn't seem to be mirrored to the monitor port - what am I missing? The port mirror configuration is straight forward so if it is something I'm missing, it must be on a different screen and I don't have a clue where to look!
Please help! I've been searching on Google but as usual, I can't seem to get the right combination of words to get me to the solution I'm hoping is out there! I'm hopefull the experts here will know the answer!
Cheers,
ak.
I'm trying to setup a port mirror on a Nortel Baystack 470-24 switch (4 in stack). The purpose of the mirror is so that I can run a IDS on a host other than the firewall itself. So, on the firewall (CentOS 5.10), when I run 'tcpdump -l -nnn -i eth1' (eth1 is the LAN facing interface), I can see all traffic heading to the LAN from the Internet in addition to other noise on the LAN. However, on the IDS, when I run the same tcpdump command as above on the interface designated as the sensor port, I only see local traffic - the traffic destined to internal hosts from the Internet doesn't seem to be mirrored to the monitor port - what am I missing? The port mirror configuration is straight forward so if it is something I'm missing, it must be on a different screen and I don't have a clue where to look!
Please help! I've been searching on Google but as usual, I can't seem to get the right combination of words to get me to the solution I'm hoping is out there! I'm hopefull the experts here will know the answer!
Cheers,
ak.