Comment on [deleted]
nbailey@lemmy.ca 9 months ago
For about a year I was running a full out of band IPS on my network. My core switch was set up with port mirroring to spit out a copy of all traffic on one port so that my Suricata server could analyze it. Then, this was fed into ElasticSearch and a bunch of big data crap looked for anomalies.
It was cool. Basically useless because all it did was complain about the same IP crawler bots as my nginx logs. But fun to setup and ultimately good for my career lol.
MigratingtoLemmy@lemmy.world 9 months ago
The problem is, you’d expect your switch to mirror all traffic, including what it is generating (switches with web servers, baseband servers/backdoors like every big manufacturer), but you can never really be sure.