178 Vulnerability ManageMent
If a network tap is used instead of the port mirroring function, then
only a limited amount of traffic may be visible to the device. is is
because not all devices are exchanging packets with devices outside of
their own network segment. When port mirroring is used on a switch,
all packets from all members of a particular network segment can be
copied to the analyzer. A network tap is used on a single network
cable to observe whatever may pass by but the conversations between
two devices on the same network would remain unobserved.
It is possible through some creative network configuration to over-
come this problem within limits. e mirroring solution is limited in
the completeness of traffic that can be examined b