I would like to try and monitor all VLANS with SO. Here is my question, if I configure one of the ports on my managed switch to output all of my VLANS(tagged) and connect this port to my SO monitor port, will SO monitor all of the VLANS?
Thanks in advance for your help.
Gerry
Thanks for the response.
I tried the configuration and had limited success. Using Wireshark, I see limited traffic (ARP, IGMP, MDNS) across all of the VLANs. However, when I establish a connection with the speedtest.net service, I do not see any of that traffic. In retrospect, since I am feeding the SO monitor port from an output port of my managed switch, I should not see all of the traffic across any one VLAN by design. This sounded like a good idea at the time but was not well thought out.
I think the solution is to simplify my home network. I intentionally made it more complex than necessary to learn about managed switches and VLANs.
Thanks for your help.
Gerry
Gerry,
Try taking a look in:
#Suricata
/etc/nsm/HOSTNAME-INTERFACE/suricata.yaml
#Snort
/etc/nsm/HOSTNAME-INTERFACE/snort.conf
#PF_RING
/proc/net/pfring/
Thanks,
Wes
Wes/Doug,
Thanks for the information. I have adjusted snaplen and interface MTU and will monitor to see if it makes a difference.
Gerry