[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [OT] HP Procurve Port mirroring and Snort



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 18/06/2007, at 5:14 PM, Jim Popovitch wrote:
On Mon, 2007-06-18 at 11:58 +0200, Andrew Miehs wrote:
Port mirroring on the HPs only seems to monitor traffic going
'into' the switch, which means I would need to mirror every single
port on the switch.

Hmmm, sounds fishy. I'm not familiar with HP or their configs, but I'll
try and help :-)

In config, does "show monitor" display display all expected ports?


Hi Jim,

Its a feature not a bug.

All the ports are there - but the port mirroring only mirrors the one direction - by design.

If you want to measure traffic between web server and load balancer for example, you need to mirror BOTH of the ports - you get the incoming traffic on both interfaces...

I am just a little worried about my switch melting if I do this with all 120 interfaces....

:-(

hp4108-1# show monitor

Network Monitoring Port

  Mirror Port: F2

  Monitoring sources
  ------------------
  E20
  F7

hp4108-1#


Cheers

Andrew

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (Darwin)

iD8DBQFGdqfOW126qUNSzvURAqEwAJ41ff+s51FWXzfYMEGuyKvvAnp/2gCePxn+
4FYMzFGjnsVTHWISbDng004=
=/dsn
-----END PGP SIGNATURE-----



Reply to: