Not be able to ping the monitoring interface for SO, and no detect events and alerts #11325
Replies: 8 comments 5 replies
-
Hi, |
Beta Was this translation helpful? Give feedback.
-
This is my configuration 👍 Thanks lot ! |
Beta Was this translation helpful? Give feedback.
-
Is there a command to check/modify the monitoring interface? |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
I have new installation ens36 instead ens35. Now i receive traffic : Thanks |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
Try creating traffic that would match your enabled NIDS rules in /opt/so/rules/nids/all.rules. For example: |
Beta Was this translation helpful? Give feedback.
-
Arp attacks related to layer 2 of OSI model. Suricata and Snort IDPS is developed to detect attacks at the higher level of OSI model. Suricata doesn't have mechanism to detect such type attacks. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
I am not able to ping from Linux1 or Linux2 to the security onion interface. And no detect alert for arpspoof attack from Linux1 to Linux2. I used VMWare workstation with Bridge and Vmnet1 (Host-only), as given in the figure.
Beta Was this translation helpful? Give feedback.
All reactions