Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Span port configuration question

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 2 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      faffi
      last edited by

      I have an Alix 2d3 (3x nic) board running 2.0 and want to configure the third interface to just dump all the traffic going in/out of the WAN to an internal machine on my LAN running snort (the snort machine has 2 nics). I saw a way of setting up a span port when using a bridged interface but that is not very ideal for me. Is there a way to do this without having to use a bridged interface for my LAN/WAN?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        From the ifconfig man page:

        span interface
                    Add the interface named by interface as a span port on the
                    bridge.  Span ports transmit a copy of every frame received by
                    the bridge.  This is most useful for snooping a bridged network
                    passively on another host connected to one of the span ports of
                    the bridge.

        Not sure why that isn't ideal, it's exactly what you want.

        There is a pf feature called dup-to (but we don't support it in the GUI) that will send duplicate copies of packets to a given host, but the only way to ensure you see all of the traffic would be to use a span port.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • F
          faffi
          last edited by

          @jimp:

          From the ifconfig man page:

          span interface
                      Add the interface named by interface as a span port on the
                      bridge.  Span ports transmit a copy of every frame received by
                      the bridge.  This is most useful for snooping a bridged network
                      passively on another host connected to one of the span ports of
                      the bridge.

          Not sure why that isn't ideal, it's exactly what you want.

          There is a pf feature called dup-to (but we don't support it in the GUI) that will send duplicate copies of packets to a given host, but the only way to ensure you see all of the traffic would be to use a span port.

          Yes, that option is exactly what I want except I don't want to do bridged networking :(

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Any particular reason? Or just a matter of preference?

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • F
              faffi
              last edited by

              @jimp:

              Any particular reason? Or just a matter of preference?

              Just preference really, I know it sounds silly but it's just how I wanted to do it. Even though it would work with bridged networking, it just isn't very ideal.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.