I'm referring to running pcap traffic through the device from a traffic server, and with the firewall *disabled* in order to focus on the IDS/IPS. Not capturing or replaying traffic from within it.
For instance:
- Promiscuous mode on any of the interfaces or the IDS?
- Any special NIC settings
- Any other tuning requirements
Thanks -