Help Please #11962
-
Hello, /etc/soversion : 2.3.270 but when i run sudo salt _ state.apply firewall I have doubts that it is a firewall configuration problem or the forward with a single NIC |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments
-
From #1720:
This is a strange configuration. Sensor nodes are intended to monitor traffic and have 2 or more NICs. If you're not going to monitor traffic, then you probably don't need a sensor node.
Please note that 2.3 reaches End Of Life in less than 4 months: You may want to take this opportunity to migrate to 2.4. |
Beta Was this translation helpful? Give feedback.
-
that is right i'am not going to monitor traffic but i think i will need forward node for filebeat configuration! |
Beta Was this translation helpful? Give feedback.
-
If you're not going to monitor traffic from a tap or span port and are just trying to collect firewall logs from your firewall, then you don't need a forward node. Please take this opportunity to move to 2.4 and make sure you review the documentation to determine the correct architecture and node types to meet your requirements: If you have further questions or problems, please start a new discussion with relevant and descriptive title in the Title field and avoid generic titles like |
Beta Was this translation helpful? Give feedback.
If you're not going to monitor traffic from a tap or span port and are just trying to collect firewall logs from your firewall, then you don't need a forward node.
Please take this opportunity to move to 2.4 and make sure you review the documentation to determine the correct architecture and node types to meet your requirements:
https://docs.securityonion.net/en/2.4/architecture.html
If you have further questions or problems, please start a new discussion with relevant and descriptive title in the Title field and avoid generic titles like
Help Please
.