SPAN port question

Our security guys wants to snort installation on a Linux box with a SPAN port to capture all traffic network (not just traffic VM). What are my options? I think I should do VMDirectPath for a 1 GB integrated network interface and turn it into a SPAN port for the virtual machine. Is there another approach, I'm missing?

Snort will be on a VM with RHEL. I try to avoid using physical blade assets simply because we need a SPAN port. I think that my best course of action will be to use DirectPath to the network card of the snap in a virtual machine.

Tags: VMware

Similar Questions

  • Spanning Ports of layer Multiple 3 jumps away

    Someone got experience spanning ports of switches which are several layer 3 jumps away network sniffing workstation?

    Hello

    You should watch ERSPAN. It uses a GRE tunnel to carry the traffic on the network.

    http://www.Cisco.com/en/us/docs/switches/LAN/catalyst6500/IOS/12.2Sx/configuration/guide/span.html#wp1048235

    Hope this helps

    Martin

  • Spanning tree question

    I have a stack of 4 switches PowerConnect 7048 core. There are unacceptable delays on the network so I'm cleaning configurations and verification spanning tree as these have been set up by he previous admin. The four active links of 10 GB, the spanning tree different reports States:

    two are

    Te3/2/1 port active
    Status: Disabled role: disabled
    Identification of the port: 128.167 shipping: 0
    Fast port: no Protection from root: No.
    Designated the bridge priority: 4096 address: 5C26.0AAA.1EA6
    Identification of the designated port: 0.0 cost of access road designated: 0
    Root regional CSE: 80:00:5 C: 26:0 A: AA:1E:A6 CST Port cost: 0
    Root Guard..................................... FAKE
    Loop Guard..................................... FAKE
    TCN Guard...................................... FAKE
    Portfast auto... TRUE

    and two are

    Te2/2/2 port enabled
    State: Forwarding role: designated
    Identification of the port: 128.112 shipping: 2000
    Fast port: no Protection from root: No.
    Designated the bridge priority: 4096 address: 5C26.0AAA.1EA6
    Identification of the designated port: 128.112 cost of access road designated: 0
    Root regional CSE: 10:00:5: 26:0 A: AA:1E:A6 CST Port cost: 0
    Root Guard..................................... FAKE
    Loop Guard..................................... FAKE
    TCN Guard...................................... FAKE
    Portfast auto... TRUE

    . I think the first one indicates a problem and all must be reported as the redirection and designated. Is that correct and if so, how can this be done?

    Thank you

    Hello

    Does not serve a disabled state. If you do not disable spanning tree, it should allow. http://downloads.Dell.com/manuals/all-products/esuprt_ser_stor_net/esuprt_networking/esuprt_net_fxd_prt_swtchs/PowerConnect-7024_Reference%20Guide_en-us.PDF page 745

  • MiniDisplay Port question

    Hello to you all!

    I have a (fast) 2009 iMac 24 inch and I also own a (Mid) 2012 MacBook Air 11 inches.

    I would like to know what cable MiniDisplay Port or love at first sight, I need to connect these two computers because although I had apple for most of my life I still know very well all the cables and other peirpherals that I need to connect both of these computers.

    Please could you link the product me to apple.com/uk official or you may also connect with amazon.co.uk

    We can't to anything by hanging the screen all ports; what you need depends on what you're trying to do by signing their other ports.

    (141990)

  • HP ZBook F0U66EA and integrated Thunderbolt port question

    Hello!

    The Thunderbolt on HP ZBook F0U66EA port will work with the new Thunderbolt optical cable to 30 m? Or for only 2 meters copper cables?

    Tnks!

    The zBook works with any cable Thunderbolt, copper or fiber.  Copper to Fiber Converter is in the cable itself, not the PC, and the cables can operate with any port Thunderbolt.

    Fiber optic cables have a much greater range than copper cables, but they won't deliver power to the terminal, the terminal must be powered from wall.

  • DIO 6040E Port question

    I have a PXI - 6040E DIO P0.0 (52 PIN) port is hooked up to a module OPTO - 22 G4ODC5 (TTL Input). When I run DIO Port COnfig.vi with map direction line the value - 1 (all the value entries Digital Out) it lights up all the inputs(PO.0-7). When I turn actually WE DO using DIO Port Write.vi the, it turns OFF. Tried to reverse the line maximum work don't wilt. All entries?

    Hello lilocomotiv,

    The behavior you describe is the default behavior of the E series. To set the States of digital lines see 266KK6YF knowledge base: affecting the default state of the digital lines on maps DAQ of E series.

  • Router Port question

    I have a switch 6224 that is not configured with any VLAN special or routing. It comes as a layer 2 switch.  I have a Sonicwall TZ210 my firewall router connected to my ISP.  I'm running into some issues related to too many switches connected together.

    I wanted to make sure that my sonicwall is connected to the appropriate port on my switch.  The guy who set up it connected the sonicwall LAN port to the port on the switch 15.  It is not setup like any special port.  Shouldn't it be plugged into one of the ports 21-24.  I have a plugged into 24 GBIC that connects to another powerconnect switch 2427.

    Thank you

    Unless you have an optical fiber with a transmitter/receiver connection.  There is no physical reason why a cable must connect on a certain port.  You désigneriez the switchport mode configuration in order to establish functional connection.

    Can answer you with your show run output and a description of your physical environment so that we can better understand or what is happening.

  • Cisco 892FSP - SPAN Ports behavior

    Dear Cisco-community,

    I'm trying to reflect an uplink port (Gi8) of my Cisco892 to a switchport (IG2). Is this a bug or a feature that I can't mirror uplinks(Gi8-9), but switchports(Gi0-7) do not work?

    Uplink does not:

    C892-(config) #monitor session 1 source interface gigabitEthernet?
    <0-9>The GigabitEthernet interface number

    C892-(config) #monitor session 1 source interface gigabitEthernet 8
    % Of incomplete orders.

    C892-(config) #monitor session 1 source interface gigabitEthernet 8?
    % Unrecognized command

    Switchport œuvres

    C892-(config) #monitor session 1 source interface gigabitEthernet 7
    C892-(config) #.

    Version:

    Cisco IOS software, software C800 (C800-UNIVERSALK9-M), Version 15.5 (3) M3, VERSION of the SOFTWARE (fc2)
    Technical support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2016 by Cisco Systems, Inc.
    Updated Tuesday, June 20, 16 13:57 by prod_rel_team

    Cisco C892FSP-K9 (revision 1.0) with 488524K / 35763K bytes of memory.
    10 gigabit Ethernet interfaces
    1 module of virtual private network (VPN)
    Configuration of DRAM is 32-bit wide
    255K bytes of non-volatile configuration memory.
    250880K bytes of ATA CompactFlash (read/write) system

    Thank you!

    I do not know the answer - but in general, you can only monitor switch ports, not routed layer 3 ports.

  • VMFS spanning test questions

    Hi gentlemen

    How VMFS_spanning test really works?

    Maual (LUN allocation) page 16 says:

    5 VMFS covering 10 GB

    Remaining unused LUNs
    50% the LUN has the storage capacity of 5 GB and 10 GB to 50%
    the LUN has between 2 and 5 GB storage capacity


    So I have 5 x 10 GB LUN and 9 x 3 and 9 x 5 GB

    According to my understanding of the instructions, VMFS_spanning test must use these LUNs 5 x 10 GB for this test.
    But this test also use LUN size of 5 GB and 10 GB, not only 5 LUN are used for this test, but all available (5 x 10 + 9 x 5 GB). Is it planned?

    As the manual says that the test runs approximately 330 min, in my case I see it runing for 21 hours now... Connect see the:

    2013-04-28 23:33:07 UTC [VM] [0] INFO: [1104] process 'Iometer.exe' is still running on x.x.x.x, retry in 60 seconds...
    2013-04-28 23:33:07 UTC INFO [VMSTAF] [0]: VM: [1105] Captured ' ' tasklist/fi \"imagename Iometer.exe\ eq'"' output on x.x.x.x.. "

    Is this correct?

    The IOMeter runs on a virtual machine? If you see IOMeter GUI then test will continue to work forever. Please see the release Workbench note of August 2012-

    PR 711199: Iometer process crashes.
    Problem: This error message is displayed indefinitely.

    2011-06-02 09:06:26 CDT [June 2, 2011 09:05:25: VM] [0] INFO: [8227] process 'Iometer.exe' is still running on 135.15.71.43, again in 60 seconds...
    2011-06-02 09:06:26 CDT [June 2, 2011 09:06:26: VMSTAF] [0] INFO: VM: [8228] Captured ' ' tasklist/fi \"imagename Iometer.exe\ eq'"' exit on 135.15.71.43 "

    When the Assistant of Installation of Workbench install STAF on Windows, it creates a scheduled task:

    schtasks/create /tn "% SYSTEMDRIVE%\STAF\startSTAF.bat" /tr startSTAF /sc onstart /ru "authority NT\SYSTEM.

    This command runs the script startSTAF.bat on the start-up of the system using the account system (no login required).

    The startSTAF.bat script contains:

    Start 'STAF' /D%SYSTEMDRIVE%\STAF\ %SYSTEMDRIVE%\STAF\bin\STAFProc.exe

    STAF Setup program creates another script, called startSTAFProc.bat, that will not start SCOTT until the user logs on the system.
    The following tests using iometer workloads: Volume_Grow, NFSClient_NFSMount_Unmount, VMFS_Spanning.
    When the test starts iometer via service STAF, iometer process does not start the iometer GUI and he waits.

    Solution: Before running the tests, perform the following steps on each Windows GOS installed on ESXi hosts. In the case otherwise, the process of iometer will hang and the tests fail after completing the process of iometer manually.
    1 see the section Guide of Certification of storage disable features on computers virtual and other parameters of the Virtual Machine for the recommended GOS settings and tools of e/s.
    2. check that these files are on each virtual machine in Windows:

    Z:\Iometer\Results
    C:\Iometer\Configs

    3. check than the: drive exists.
    4. on each Windows virtual machine, manually run Iometer and verify that it works correctly: GUI IOmeter and Dynamo Windows are open.
    5. accept the license agreement of Iometer and disable the firewall when you are prompted.
    6. turn on the auto administrator account connection.
    7 kill service STAF existing process:
    Taskkill /F /IM STAFProc.exe 2 > ZERO
    8 remove the task created by the Installation Wizard.
    schtasks/delete /tn startSTAF /f 2 > NUL10.
    9 start the STAF service by running the startSTAFProc.bat script to allow iometer.exe GUI must be started by the test.
    10. run tests requiring iometer.
    11. after running the tests that require iometer, restore the scheduled task that was deleted previously:
    schtasks/create /tn "% SYSTEMDRIVE%\STAF\startSTAF.bat" /tr startSTAF /sc onstart /ru "authority NT\SYSTEM.

  • SPAN and TCP RST

    I know that a Cisco IDS allows to inject a TCP RST in a SPAN port in order to kill a connection.

    My question is: this technique works only when you switch ports SPANing, or will it also work when SPANing VLAN? I was told that is not possible. Suppose a 6000 series switch.

    Regards, Jeff

    Some switches allow you to send TCP reset via the Span port and some do not. TCP resets through the port Span are therefore very switch to load, and you can read your documentation of switches. (Not all Cisco switches has exactly the same).

    IF the switch allows TCP resets the Span port then the resets should work for port and Vlan Span sessions with a few warnings that you can read below.

    IF the switch does not TCP resets the Span port, then TCP resets do not work whatever the Span session type you have.

    In a Session of Span Port, the port being calibrated must be in the same vlan that is configured for the destination span for TCP port resets to recover the vlan good work.

    If you try to Port Span ports of different VLAN, then the sensor will alarm OK, but the TCP reset works only on attacks that are visible on the same vlan assigned to the destination span port.

    VLAN spans have the same limitations. If you cover a single virtual LAN vlan is attributed to the destination span port, then the TCP resets will get to the vlan right and should work.

    If extend you from several VLANs and then the TCP resets will only work on the same vlan assigned to the destination span port.

  • newbie Y560P laptop questions

    Lenovo forums are very informative and I looked for answers to my questions and have found some but not all. I recently (St Patty's day) ordered an ideapad y560P. I should have asked these questions before buying but there was an e-coupon deal that ends the day of St patty, I had wanted a laptop pretty advanced for a while so I jumped. Life is not perfect!

    1. a clean install of windows is possible with recovery disks that Lenovo provides? If this is not the case, what is the best way to do it?

    2. the Y560P can fully utilyze the new SATA 3 SSD as boot drive? Void the warranty?

    3. wait for Lenovo to ship my laptop until the Sandy Bridge sata port questions/reminder are developed?

    4. someone here successfully using imaging software (like Acronis true image} on their laptops?)

    Sorry for the newbie questions. I built my own desktops for years, but this will be my first laptop. Time passes! Thanks in advance for any help.

    Hey, I'll do my best to respond to these:

    (1) actually, no discs are technically provided by Lenovo. Your system comes with a separate, partition that contains a recovery image. That being said, you can create a set of recovery disks by running their usefulness (comes pre-installed). When you use these disks, it basically as a duplication process. So yes, you can do a clean install, if you think it their image pre-built a clean installation

    (2) not sure about the 3 SATA drives, but drives does not cancel your comprehensive guarantee. I would always keep the original drive where the system needs to be sent, but I think that the RAM and CPU are considered as 'evolutionary customer options' and are therefore not guarantee-killers.

    (3) from what I've read, Lenovo has already stopped the lines with questions of Sandy Bridge. None of these units should be delivery to consumers. If I remember correctly, it only affected some of the i7 lines. If you have concerns, you can always call Lenovo with your serial number, and they can check if the unit is affected. However, Lenovo has been very quick to fix this, I just couldn't see their shipping defective units known to customers.

    (4) Acronis and Ghost work quite well, assuming it is a standard drive. I could not find any problems with people using either a product on the readers of the so-called "hybrid".

    Hope that helps a bit!

  • How can I configure Spanning Tree

    Hello

    I have several core Dell passes using PowerConnect 6224 s most - these ink in my Cisco provider kit. We run several VLAN and have redundant links between stacked switches.

    I have read up on top of the tree covering weight and have the following tasks:

    1 map of the network - including the ID of the root bridge, root ports, roads blocked, age max and time of helo

    Once I made my analysis information, I don't know how to better optimize the covering tree config, so far I have:

    1. make sure RSTP is enabled on all switches
    2. make sure that all edge ports have spanning port configured fast shaft
    3. not declare spanning port fast shaft on the links between switches
    4 force speed and duplex settings on all ports to link between the switches (I guess that's because the auto negotiate takes more time?)

    I'm not sure is:
    1 can I use BPDU guard and if so, where?
    2 can I use root guard and if so, where?

    I read the informative article by Todd: http://en.community.dell.com/support-forums/network-switches/f/866/t/19465205.aspx

    But, I don't know where\whether I should to configure the options of guard - am happy to provide additional information as needed.

    Thank you

    Spanning Tree BPDU Guard is used to disable the port where a new device tries to enter the already

    existing STP topology. Thus the devices, which were originally not part of STP, are not allowed to

    influence the STP topology. If the Enable value, when a BPDU is received on a port of the tip, this port is disabled. Once the port has been disabled it requires manual intervention to be reactivated.

    Spanning Tree Root Guard is used to prevent change of the root of a Spanning Tree instance

    in an unexpected way. The priority of an ID of adjustable bridge to zero but another bridge with a low mac ID

    address could also set its priority to zero and take root.

    Both are defined globally on the switch. If you have any possibility of other network devices being plugged into the switch without your knowledge. It may be a good idea to these permits after that STP is configured on the network. That way if someone randomly connected network with STP on this device, it will not throw your network for a loop.

    Here are some good white pages on the tree covering weight

    www.Dell.com/.../app_note_13.pdf

    www.Dell.com/.../app_note_1.pdf

    www.Dell.com/.../pwcnt_MSTP_interoperability.pdf

    Thank you

  • IPS Inline Mode span configuration

    In Inline Mode IPS V5, the second interface (where a package goes out) a paired interface must be configured as a span port or a regular port? Where can I find more information about it? Thank you.

    Need more information about your configuration set. Generally speaking, the answer is "regular shipping". Your use of "span" leads me to believe that you are being implemented in a switch. In this case, be advised that if you try to loop in the same switch that you originally, you will need to have this second port in a vlan different. The sensor does not spread, it is a "virtual" thread

  • Setting port channel between UCS - FI and MDS 9124 (Mode F)

    Dear team,

    We tried to create the channel of port between UCS FI and MDS 9124

    But the port channel do not take action in mode F on MDS 9124

    FI is in host FC end Mode

    We have allowed FC uplink on FI trunking

    We have activated NPIV on MDS

    We have activated the MDS trunk

    FI and MDS in default VSAN

    To check that we have changed the way FI FC channels mode and switch port became active, but in E mode

    When we enabled CF trunking of uplink on the port mode FI channels and FC Switching became active in mode TE

    but in both cases above, showflogi database shows WWPN of SAN alone does not have the any fi.

    How to achieve this?

    Have read that no need to change the mode switching mode of CF swicthing and keep FC Endhost way

    SO how to channel ports with mode F MDS and FI (Display Mode as NProxy)

    What is it has nothing to do with the MDS NX - OS version? (https://supportforums.cisco.com/thread/2179129)

    If yes how to put as license for ports came with the camera and we don't have any CAP/PAK or license file as she came

    with license

    Also, we saw 2 files available for download (m9100-s2ek9-kickstart - mz.5.2.8 .bin and m9100-s2ek9 - mz.5.2.8 .bin b b) to use

    Thanks and greetings

    Jose

    Hi Jo Bo.

    What version of the software if your MDS race?

    On your UCS do connect nxos and show ficelleStringString ficelleT inteface and find the mac address.

    It is possible that you could be hitting the bug below. If this is the case, you may need to update the firmware on your MDS.

    Add MAC YES '002a6a', '8c604f', '00defb' for 5 k/UCS-FI

    http://Tools.Cisco.com/support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId= CSCty04686

    Symptom:

    Link change cannot connect any other Nexus or other Cisco Switch in mode VAN with a port channel F.   Question can be viewed in older versions of 5.1

    5.1.3.N1.1a

    but not later

    5.1.3.N2.1c

    Release. Question is also found in

    5.2 (1) N1 (1)

    and

    6.0 (2) N1 (1)

    and later versions.

    Conditions:

    Nexus configured for the link SAN PortChannels or NPIV Nexus mode connected to the UCS via regular F port channel where UCS VAN VAN edge mode switch: YES switch manufactured FI or another Cisco UCS Port WWN: xx:xx:00:2 has: 6a: xx:xx:xx or xx:xx:8 c: 60:4f:xx:xx:xx

    Workaround solution:

    Turn-off on Nexus 5 k TF-port question link mode does not happen with standard F-PORT SAN to remove Portchannel config

    Other Description of the problem:

    To check question collect please see the flogi-event history internal errors whenever the port is attempted OLS, AMENDMENTS, PBA counters will increment. This can be determined via the following output, view port internal info to see all the internal-historic port of error events

  • Use of ISE 3355 device of the two GigE ports

    I'll put in place six ISE 3355 3 devices in a data center in another 3. They just installed a new infrastructure of server using 5596 Nexus and Nexus 2248TP farm top of rack switches.

    I am looking for documentation on how to make the collection of NETWORK adapters on the way 3355 or some connect Gig0 to FEX101 and Gig1 to FEX102. Or simply set up a channel using LaCP port between the two different groups of FEX?

    Sent by Cisco Support technique iPhone App

    Hello

    This is not supported, you can not team or balance the load or use redundant interfaces on devices of the ISE. You can only use a span port dedicated for ISE deployments, or use the links to crossover to a deployment ipep in HA mode.

    Thank you

    Tarik Admani
    * Please note the useful messages *.

Maybe you are looking for