 From:  Dinesh Nair <dinesh at alphaque dot com>
 To:  Jim Gifford <jim at giffords dot net>
 Cc:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Re: [m0n0wall] interface mirror
 Date:  Thu, 18 Mar 2004 01:11:49 +0800 (MYT)
On Wed, 17 Mar 2004, Jim Gifford wrote:

> Using a hub between your WAN device and your WAN port, and hanging the
> IDS off of that hub is one way to do it.  That restricts your bandwidth,
> but chances are the WAN device is already restricted anyway.  Using the
> ethernet tap is probably the purest solution.

there's another, using freebsd's ng_tee netgraph node. it's not a part of
the default m0n0wall images, but you should be able to follow the
instructions at http://m0n0.ch/wall/hack/ to include both ng_ether and
ng_tee into the /modules directory, just as dummynet and ipfw modules are

read the freebsd man page for ng_tee at
for what it does. you'd basically be connecting the left hook to the upper
hook of the wan interface, the right node to the lower hook. then connect
left2right to the lower hook of the lan(ids) and right2left to the upper
hook of the lan (ids) interface.

