Configure TP-Link TL-SG108E Switch #11780
-
Version2.4.20 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationother (please provide detail below) Hardware SpecsMeets minimum requirements CPUQuad Core RAM20GB Storage for /300GB Storage for /nsm300GB Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusNo, one or more services are failed (please provide detail below) Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailDear all forumers, I had installed SO 2.4.20 and completed the so-setup but I didn't find the setup for whether to use TUN/Span port selection at so-setup. Another questions is I had configured router TP-Link TL-SG 108E to mirror on port 8 but the link is down. How to enable it and let it capute the inbound traffic? There is no ip address associated with it yet. Please help. Thanks. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 5 comments 1 reply
-
Monitor port on the Onion doesn't care what you connect it to. But it needs link. Might be a config issue on that port-8. |
Beta Was this translation helpful? Give feedback.
-
Derar all forumers, I just enable the port mirroring feature on port 8 for my TP-Link TL-SG108E switches. This is the screenshot of the switches port mirroring. |
Beta Was this translation helpful? Give feedback.
-
Dear all forumers, Please help. |
Beta Was this translation helpful? Give feedback.
-
Looks like you need to 'enable' ingress / egress on each port you want to mirror traffic out to port 8. While you troubleshoot your switch you can use the influxdb dashboard to monitor ingested traffic speed and give you insight into when your Security Onion box starts seeing traffic. https://docs.securityonion.net/en/2.4/influxdb.html?highlight=influxdb#influxdb |
Beta Was this translation helpful? Give feedback.
-
Good info here. |
Beta Was this translation helpful? Give feedback.
Looks like you need to 'enable' ingress / egress on each port you want to mirror traffic out to port 8.
While you troubleshoot your switch you can use the influxdb dashboard to monitor ingested traffic speed and give you insight into when your Security Onion box starts seeing traffic. https://docs.securityonion.net/en/2.4/influxdb.html?highlight=influxdb#influxdb