Sensor settings in the OSSIM System
The setting of Sensor is particularly important. The specific setting method is similar to that of the sniffer. Many people have installed the sniffer. In large networks, this method is not as simple as accessing the network. As a network administrator, you should be clear about the specific circumstances of the managed network environment. 2-2 shows the network topology of an enterprise.
Figure 2-2 how to select the position of the sniffer
Next we will mainly discuss the sniffing methods in exchange and routing networks.
1. Exchange Network
Port Mirroring is the easiest way to capture traffic in a switched network. However, the switch must support the Port Mirroring function and have an idle Port, you can insert a sniffer. Most switches above the middle-end support port mirroring, but the degree of support varies.
Devices that support SPAN:
Common Tp-link vswitches with image functions include tplink sf2005 5-port image vswitches.
Tp-link 2428WEB 24 port network-managed image Switch
Cisco WS-C6509, WS-C4006, WS-C3750G-24T-E, WS-C3550-48EMI, WS-C2950G-24-EI Huawei S2008/S2016/S2026/S2403H/S3026 support port mirroring.
Figure 2-3 Sensor deployment in a switched network