Security Onion only for HIDS #13435
Replies: 2 comments 4 replies
-
What do you mean "As there is no possibility to mirror Network traffic between VMs inside ESXI"???? |
Beta Was this translation helpful? Give feedback.
2 replies
-
Thanks very much for info!!!!!!
…On Mon, Aug 5, 2024, 22:32 TotieBash ***@***.***> wrote:
Yes. If you enable "promiscuous mode" on that specific port group and
SO-forwarder "monitor" interface is on the same port group your SO will get
a copy of every packet in/out of that particular port group.
—
Reply to this email directly, view it on GitHub
<#13435 (reply in thread)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AKQVLRSHXTGVYNDVR5HAIJDZP7ONDAVCNFSM6AAAAABMABDH5CVHI2DSMVQWIX3LMV43URDJONRXK43TNFXW4Q3PNVWWK3TUHMYTAMRUGY4TINI>
.
You are receiving this because you authored the thread.Message ID:
<Security-Onion-Solutions/securityonion/repo-discussions/13435/comments/10246945
@github.com>
|
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi all,
As there is no possibility to mirror Network traffic between VMs inside ESXI I need advice for distributed Install as I want to cover HIDS at least:
1.) Install Manager
2.) Install Search Node
3.) Possibly Install Fleet node ?
Would you also go with this setup?
Thanks.
Beta Was this translation helpful? Give feedback.
All reactions