3 ms·
>I'd have a rule of no analysis of non-tap data. This is a ridiculous rule, you are cutting off your nose to spite your face. The saying "perfect is the enemy
by windowsworkstoo 11y ago
>I'd have a rule of no analysis of non-tap data.
This is a ridiculous rule, you are cutting off your nose to spite your face. The saying "perfect is the enemy of good" comes to mind.
To your above point
>maybe missing filters or too wide an address space
There is merit in just capturing a shitload more than you need (provided of course, you're not trying to cap a full 10Gbit) because it is often the filters that are the cause of any "performance" issues, however you define that.
- DyslexicAtheist 11y agothe rule depends on context which I failed to mention. I agree with you in context of non critical infrastructure. Though I'm not talking about web apps in AWS but places where you still want to have your own datacenter like in a banking or telecoms, or insurance or medical environments. EDIT: whether you allow any access to a node for whatever purpose other than the software that was meant to run on that node would probably depend on what damage is done if that node goes down. If the damage is a blip in statistic and you can live with that fine but that's not always the case
- windowsworkstoo 11y agoYou're still overthinking things and dealing in hypotheticals it sounds like to me. Almost the only time you would want a physical tap is if you need a permanent tap capturing everything over a long term - often for the purpose of running through an IDS/IPS, an even then SPAN/RSPAN/ERSPAN works pretty well. Even in those industries you mention, most of the other time you are doing a capture is to troubleshoot something, so you don't need to run things for a long time, nor does any "perf issue", which is overstated, probably matter, since things are possibly already half way to fucked. And the compliance argument doesn't hold either vis-a-vis installing tcpdump - your processes and policies would be written as such to allow for debugging (or should be)