<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Span port configuration question]]></title><description><![CDATA[<p dir="auto">I have an Alix 2d3 (3x nic) board running 2.0 and want to configure the third interface to just dump all the traffic going in/out of the WAN to an internal machine on my LAN running snort (the snort machine has 2 nics). I saw a way of setting up a span port when using a bridged interface but that is not very ideal for me. Is there a way to do this without having to use a bridged interface for my LAN/WAN?</p>
]]></description><link>https://forum.netgate.com/topic/32596/span-port-configuration-question</link><generator>RSS for Node</generator><lastBuildDate>Tue, 11 Aug 2026 15:21:54 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/32596.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 10 Apr 2011 22:08:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Span port configuration question on Tue, 12 Apr 2011 15:36:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jimp">@<bdi>jimp</bdi></a>:</p>
<blockquote>
<p dir="auto">Any particular reason? Or just a matter of preference?</p>
</blockquote>
<p dir="auto">Just preference really, I know it sounds silly but it's just how I wanted to do it. Even though it would work with bridged networking, it just isn't very ideal.</p>
]]></description><link>https://forum.netgate.com/post/274725</link><guid isPermaLink="true">https://forum.netgate.com/post/274725</guid><dc:creator><![CDATA[faffi]]></dc:creator><pubDate>Tue, 12 Apr 2011 15:36:29 GMT</pubDate></item><item><title><![CDATA[Reply to Span port configuration question on Tue, 12 Apr 2011 11:31:49 GMT]]></title><description><![CDATA[<p dir="auto">Any particular reason? Or just a matter of preference?</p>
]]></description><link>https://forum.netgate.com/post/274687</link><guid isPermaLink="true">https://forum.netgate.com/post/274687</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Tue, 12 Apr 2011 11:31:49 GMT</pubDate></item><item><title><![CDATA[Reply to Span port configuration question on Tue, 12 Apr 2011 05:58:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jimp">@<bdi>jimp</bdi></a>:</p>
<blockquote>
<p dir="auto">From the ifconfig man page:</p>
<blockquote>
<p dir="auto">span interface<br />
            Add the interface named by interface as a span port on the<br />
            bridge.  Span ports transmit a copy of every frame received by<br />
            the bridge.  This is most useful for snooping a bridged network<br />
            passively on another host connected to one of the span ports of<br />
            the bridge.</p>
</blockquote>
<p dir="auto">Not sure why that isn't ideal, it's exactly what you want.</p>
<p dir="auto">There is a pf feature called dup-to (but we don't support it in the GUI) that will send duplicate copies of packets to a given host, but the only way to ensure you see all of the traffic would be to use a span port.</p>
</blockquote>
<p dir="auto">Yes, that option is exactly what I want except I don't want to do bridged networking :(</p>
]]></description><link>https://forum.netgate.com/post/274659</link><guid isPermaLink="true">https://forum.netgate.com/post/274659</guid><dc:creator><![CDATA[faffi]]></dc:creator><pubDate>Tue, 12 Apr 2011 05:58:25 GMT</pubDate></item><item><title><![CDATA[Reply to Span port configuration question on Mon, 11 Apr 2011 18:41:27 GMT]]></title><description><![CDATA[<p dir="auto">From the ifconfig man page:</p>
<blockquote>
<p dir="auto">span interface<br />
            Add the interface named by interface as a span port on the<br />
            bridge.  Span ports transmit a copy of every frame received by<br />
            the bridge.  This is most useful for snooping a bridged network<br />
            passively on another host connected to one of the span ports of<br />
            the bridge.</p>
</blockquote>
<p dir="auto">Not sure why that isn't ideal, it's exactly what you want.</p>
<p dir="auto">There is a pf feature called dup-to (but we don't support it in the GUI) that will send duplicate copies of packets to a given host, but the only way to ensure you see all of the traffic would be to use a span port.</p>
]]></description><link>https://forum.netgate.com/post/274574</link><guid isPermaLink="true">https://forum.netgate.com/post/274574</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Mon, 11 Apr 2011 18:41:27 GMT</pubDate></item></channel></rss>