Skip to content
This repository has been archived by the owner on Nov 4, 2022. It is now read-only.

Decapsulate ERSPAN #227

Open
MaxDiOrio opened this issue Aug 2, 2020 · 0 comments
Open

Decapsulate ERSPAN #227

MaxDiOrio opened this issue Aug 2, 2020 · 0 comments

Comments

@MaxDiOrio
Copy link

Seems like most network utilities are now building in support for ERSPAN decapsulation. From what I've been able to test so far, there is no reliable way to decapsulate ERSPAN traffic before stenographer grabs it. We're trying to send ERSPAN Type II traffic directly from VMWare vDS to a Linux host that's being used for NIDS (Security Onion), that uses Steno to capture the packets.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant