Skip to content
Discussion options

You must be logged in to vote

If you're not going to monitor traffic from a tap or span port and are just trying to collect firewall logs from your firewall, then you don't need a forward node.

Please take this opportunity to move to 2.4 and make sure you review the documentation to determine the correct architecture and node types to meet your requirements:
https://docs.securityonion.net/en/2.4/architecture.html

If you have further questions or problems, please start a new discussion with relevant and descriptive title in the Title field and avoid generic titles like Help Please.

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants