Network Tap Splitter #13963
Replies: 2 comments 6 replies
-
You just need to configure an additional monitor-interface (ex. "sudo so-monitor-add eth2"). |
Beta Was this translation helpful? Give feedback.
-
The answer is still "so-monitor-add". You will take both "Montitor/Tool" A and B interfaces coming from Gigamon and connect it to Security Onion. If both interfaces are new and has not been added to SO then you issue the command against both interfaces. Assuming interface names are eth1 and eth2:
You can add multiple monitor/sniffer interface to SO and so-monitor-add will take the interface and add it to "bond0" which aggregates the interfaces. You can check bond0 interfaces details with "nmcli device status" or with semi-gui "nmtui". |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
We are looking to use a Gigamon G-Tap AS-F. It copies the send and receive traffic to separate ports and does not aggregate. Does security onion support this? Are there any special configurations within Oracle Linux that need to be made? Thank you.
Beta Was this translation helpful? Give feedback.
All reactions