Elastic Agents on Multiple Subnets #12781
-
Version2.4.60 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationairgap Hardware SpecsExceeds minimum requirements CPU16 RAM128 GB Storage for /5 TB Storage for /nsm10 TB Network Traffic Collectiontap Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailCan someone provide some guidance on the deployment of Elastic Agents in a segmented network where there are multiple VLANs and site-to-site tunnels where the agents might not have "line of sight" access to the SO Manager? Do the agents need direct connectivity to the manager or can they be configured to ship their logs through a forward node? Also, if we have agents on networks where there is NAT translation, how do we configure the fleet agent settings when we need to have the agents use multiple different IPs to reach the manager based on what subnet they are on? Thanks for any guidance. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 6 replies
-
Are you able to deploy a standalone fleet node? https://docs.securityonion.net/en/2.4/architecture.html#elastic-fleet-standalone-node |
Beta Was this translation helpful? Give feedback.
-
So I guess I'm a little confused about that node type. Is that just for managing the agents? Do the actual agents send logs to the manager? Is there a list of documented ports that need to be opened for each of these scenarios? Thank you! |
Beta Was this translation helpful? Give feedback.
Yes, I actually found the following post that was extremely helpful and solved our issue:
#12583 (comment)