Summary

[ LiB ]  

In this chapter, you learned that you must configure switches in various ways to send traffic to a sensor's monitoring port for IDS analysis. Traffic can be captured by port, direction (ingress or egress), VLAN membership, or conditions matching an ACL. We learned that SPAN and RSPAN are Cisco features that allow traffic to be captured for IDS analysis. For the Catalyst 6500 switches, you can capture traffic using VLAN or IOS ACLs. You can control VLAN traffic to be captured on a 6500 switch by using the clear trunk and set trunk commands.

[ LiB ]  


CSIDS Exam Cram 2 (Exam 642-531)
CSIDS Exam Cram 2 (Exam 642-531)
ISBN: N/A
EAN: N/A
Year: 2004
Pages: 213

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net