<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Installing a NIDS with a passive Ethernet tap</title>
	<atom:link href="http://jcostom.wordpress.com/2009/04/26/installing-a-nids-with-a-passive-ethernet-tap/feed/" rel="self" type="application/rss+xml" />
	<link>http://jcostom.wordpress.com/2009/04/26/installing-a-nids-with-a-passive-ethernet-tap/</link>
	<description>186,000 miles per second, it&#039;s not just a good idea, it&#039;s the law.</description>
	<lastBuildDate>Sun, 19 Dec 2010 17:24:45 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: What is a &#8220;network intrusion detection system (NIDS)&#8221;?</title>
		<link>http://jcostom.wordpress.com/2009/04/26/installing-a-nids-with-a-passive-ethernet-tap/#comment-57</link>
		<dc:creator><![CDATA[What is a &#8220;network intrusion detection system (NIDS)&#8221;?]]></dc:creator>
		<pubDate>Thu, 23 Sep 2010 06:54:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.jasons.org/?p=235#comment-57</guid>
		<description><![CDATA[[...] Installing a NIDS with a passive Ethernet tap « In Other Words [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Installing a NIDS with a passive Ethernet tap « In Other Words [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Tedesco</title>
		<link>http://jcostom.wordpress.com/2009/04/26/installing-a-nids-with-a-passive-ethernet-tap/#comment-50</link>
		<dc:creator><![CDATA[Mike Tedesco]]></dc:creator>
		<pubDate>Wed, 18 Nov 2009 18:51:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.jasons.org/?p=235#comment-50</guid>
		<description><![CDATA[I am using Ubuntu and have followed your post.  On PC eth2 and eth3 I am not getting any
link lights.  In turn there are no receiving any packets.   I&#039;ve been monitoring /proc/net/dev.  If I plug the cable from eth2 or eth3 directly into a switch the port come up and start working.  I had assigned them private IP on my network and they worked perfectly.  Any thoughts?
 ]]></description>
		<content:encoded><![CDATA[<p>I am using Ubuntu and have followed your post.  On PC eth2 and eth3 I am not getting any<br />
link lights.  In turn there are no receiving any packets.   I&#8217;ve been monitoring /proc/net/dev.  If I plug the cable from eth2 or eth3 directly into a switch the port come up and start working.  I had assigned them private IP on my network and they worked perfectly.  Any thoughts?<br />
 </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Smith</title>
		<link>http://jcostom.wordpress.com/2009/04/26/installing-a-nids-with-a-passive-ethernet-tap/#comment-49</link>
		<dc:creator><![CDATA[Mark Smith]]></dc:creator>
		<pubDate>Tue, 28 Jul 2009 14:46:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.jasons.org/?p=235#comment-49</guid>
		<description><![CDATA[Your comment about the safety of this device, that you&#039;ll never accidentally transmit on the tapped line because you&#039;re only using the RX pair, is no longer true.  Many NICs these days will attempt to autodetect the MDI (The &quot;switch-or-host&quot;iness of an interface).  If they&#039;re not receiving anything, they&#039;ll try sending a burst of data on the RX pair and see if they hear anything on the TX pair.
At least, this was my experience when putting together the talk I&#039;ll be giving in the DefCon SkyTalks this year (2009).
But, otherwise, this page is cool indeed.  :-)
-Mark]]></description>
		<content:encoded><![CDATA[<p>Your comment about the safety of this device, that you&#8217;ll never accidentally transmit on the tapped line because you&#8217;re only using the RX pair, is no longer true.  Many NICs these days will attempt to autodetect the MDI (The &#8220;switch-or-host&#8221;iness of an interface).  If they&#8217;re not receiving anything, they&#8217;ll try sending a burst of data on the RX pair and see if they hear anything on the TX pair.<br />
At least, this was my experience when putting together the talk I&#8217;ll be giving in the DefCon SkyTalks this year (2009).<br />
But, otherwise, this page is cool indeed.  <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /><br />
-Mark</p>
]]></content:encoded>
	</item>
</channel>
</rss>

