• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 485
  • Last Modified:

I need a 48 port gigabit switch capable of VSPAN, ASAP.

We've had very suspicious activity internally, and I currently have a 3com baseline switch with no monitoring capabilities.

I have a few cisco 2950's, but they can only SPAN on a single port at a time.

What I need is a 48+ port gigabit switch that will let me span on the entire VLAN at once, and I need to order it yesterday!
0
Derekleu
Asked:
Derekleu
  • 4
  • 3
  • 2
  • +1
1 Solution
 
NAORCCommented:
Netgear GSM7248

Product Link: http://www.broadbandbuyer.co.uk/Shop/ShopDetail.asp?ProductID=2660
                    http://www.novatech.co.uk/novatech/specpage.html?NGR-GSM724

Netgear website link: http://www.netgear.com/products/details/GSM7248.php

For some reason they dont have very good reviews on the web, but i have several of them in use and i think theyre brilliant!
0
 
DerekleuAuthor Commented:
GSM7248, I am about to place this order, you are sure this will let me mirror 47 ports into 1 so I can attach a PC with IDS software on it?

0
 
NAORCCommented:
5 mins... on hold to netgear as we speak to confirm it.
0
Identify and Prevent Potential Cyber-threats

Become the white hat who helps safeguard our interconnected world. Transform your career future by earning your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

 
NAORCCommented:
Netgear have just confirmed that the switch does allow that but when you receive the switch you will need to upgrade the firmware before use.

If the switches do not do this, then i am sorry, but i am just passing on the information that the product manufacturer gave to me.
0
 
ECNSSMTCommented:
I got the 24 port Gigabit version GS724T at home (the GSM version is suppose to have better management capabilitites and a console port if I remember correctly)  and use it with ethereal to do port monitoring on those special occassions. so yes.  I'm kinda surprised about the upgrade of the firmware comment though.

I am suprised that you are not looking for a Cisco solution like a module NMI if you have something like a 6509.  

Also if you are installing HIDS clients on suspect devices, they should forward irregardless of the capabilities of the switch.

Regards,  
0
 
DerekleuAuthor Commented:
I called Netgear, they told me the GSM7248 only supports port to pot mirroring, and that the GSM7352S is the only one that can do vlan to port mirroring.

They also told me that there is a planned firmware by which the GSM7248 will be able to do vlan mirroring.

I had not planned on deploying HIDS, my users are very very picky and I have not seen an unintrusive windows based solution.
0
 
ECNSSMTCommented:
OK if that's the official word from Netgear <grin>.  I've spent the last hour looking at the Netgear website to see if I could find wording that could parallel the GS724T config page without success.  


*******************************************************************************                      
Monitor
This page allows you to configure any port's incoming and/or outgoing traffic to be mirrored to a pre-defined sniffer port.

Sniffer Mode:

Disable - disable port mirroring globally.

RX - mirroring only the ingress traffic to the designated source ports.

TX - mirroring only the egress traffic to the designated source ports.

Both - mirroring both incoming and outgoing traffic on the designated source ports.


Sniffer Port: Select from 1 to 24 ports .

Source Ports: Select any number of ports to be monitored (mirrored). The ports can not be the Sniffer port.
*************************************************************************************
This is the version of the firmware I got...

Product Name  GS724T  
Firmware Version  V1.0.0_0429  
Protocol Version  2.001.002  


Again, I'm surprised by the information that is presented.

oh well...
0
 
JFrederick29Commented:
Not sure what your budget is but the Cisco 2960 will do what you are looking for.

WS-C2960G-48TC-L

http://www.cisco.com/en/US/products/ps6406/index.html
0
 
DerekleuAuthor Commented:
ECNSSMT: Strange, very strange. Netgear engineer told me that I absolutely could not mirror more than one port, and that it was a possibility in the next firmware. Maybe the difference lies between the 24 and 48 port parts.

JFrederick29: I am looking into that cisco part. Are you absolutely sure it supports bi-directional VSPAN?
0
 
JFrederick29Commented:
From this: (http://www.cisco.com/en/US/products/ps6406/products_configuration_guide_chapter09186a00805fde07.html#wp1199491)

Source VLANs
 
VLAN-based SPAN (VSPAN) is the monitoring of the network traffic in one or more VLANs. The SPAN or RSPAN source interface in VSPAN is a VLAN ID, and traffic is monitored on all the ports for that VLAN.

VSPAN has these characteristics:

•All active ports in the source VLAN are included as source ports and can be monitored in either or both directions.
0
 
DerekleuAuthor Commented:
Points!

Thanks for assist guys, it seems that the cisco 2960 it is.

0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

  • 4
  • 3
  • 2
  • +1
Tackle projects and never again get stuck behind a technical roadblock.
Join Now