Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

1
Looking for best practice/advice for running an IDS from a VMWare host using multiple nics
Post Body

So long story short, I've got a spare server with ESXi 6.7 and I want to throw a linux distro running SNORT onto the machine. The host has 4 network cards and 3 of them will be on a dedicated "monitoring" vswitch with promiscuous mode enabled.

My network is three "distribution" switches (users) they all have trunked uplinks to my core switch-stack. Also plugged into the core are the servers and firewall.... I'm mostly interesting in what the users are doing - I've got plenty of server monitoring in place already.

My plan was:

1) create a port-mirroring "monitor" (target) port on each of the three distribution switches

2) turn on port-mirroring on the distribution switches for all ports EXCEPT the monitoring port AND the trunk uplink ports

3) connect the three switches monitoring ports to three of the NICs on my server

I was hoping that this would allow me to monitor all of the user traffic without generating any additional traffic between switches or on the core. Will this work? Or would I be better off monitoring at the core switch instead?

Author
Account Strength
100%
Account Age
11 years
Verified Email
Yes
Verified Flair
No
Total Karma
11,779
Link Karma
1,595
Comment Karma
10,074
Profile updated: 2 days ago
Posts updated: 7 months ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
4 years ago