Force10 Networks 100-00055-01 manual Capturing to a Host CPU

Models: 100-00055-01

1 132
Download 132 pages 61.04 Kb
Page 23
Image 23
Capturing to a Host CPU

Capturing to a Host CPU

Captured traffic can be sent to a host CPU through a libpcap library interface, where it can be made available to applications for analysis. A typical implementation provides IDS/Snort acceleration because of the hardware assist.

Figure 10 Capturing Matched Traffic via the libpcap Interface

 

PB-10GE-2P

tcpdump

 

Snort

Custom app

 

 

libpcap

SW

 

 

 

 

 

 

Matched Traffic

HW

M1

P1

P0 M0

 

 

 

Traffic to

 

 

 

monitor

fn90035mp

Use the P-Series in an integrated security monitoring solution through the management port. The P-Series comes with support for Sguil NSM (see Network Security Monitoring on page 43).

Figure 11 Creating a Network Monitoring Solution with the P-Series

 

 

 

PB-10GE-2P

 

 

 

 

 

Custom app

 

 

libpcap

 

SW

 

 

 

 

 

 

 

Matched Traffic

 

HW

M1

P1

P0 M0

Mgmt

Port

 

 

 

 

Traffic to

Custom

 

 

 

security

 

 

 

monitor

 

 

 

monitoring

 

 

 

 

 

 

 

 

application

fn90036mp

P-Series Installation and Operation Guide, version 2.3.1.2

23

Page 23
Image 23
Force10 Networks 100-00055-01 manual Capturing to a Host CPU