We have 3 switches in our building that all connect back to a distribution switch.
The 3 switches on the first floor are Extreme Networks. The distribution switch is a Cisco 4507r
1. What is the easiest way to monitor each switch with an IDS? Do I need a physical connection from the IDS box, to each switch?
2. The inter-vlan routing occurs in the distribution switch (Cisco 4507r). Would it be possible to monitor ALL vlans with port monitoring? Or again, will I need a separate physical connection for each switch and each VLAN.
Using a dell server running RH Enterprise with Snort 2.8.4