security onion

  1. J

    [TUTORIAL] Proxmox + Security Onion without OVS

    Since there is a complete lack of SPAN/Mirror examples using Linux Bridges into Security Onion, I thought I'd post what got working.... Also is an example using multiple bridge mirrors, which is discussed but never actually shown anywhere. Disclaimer, I am still in the very early stages of...
  2. L

    Security Onion

    Hello, is it possible to mirror the network traffic of 1 virtual port in proxmox without tc? vmbr0 --> 6 virtual ports (important ens33, ens18) i want to mirror ens33 to ens18 that the Security Onion can only see her traffic is that possible without tc because tc not working for me Greets
  3. J

    Open vSwitch Port Mirror problem (SNORT/ZEEK/Security Onion)

    A fresh install of proxmox 6.2-10. I am trying to configure port mirroring with open vswitch. I installed open vswitch via apt install openvswitch-switch. I am running version 2.12 root@pve:~# ovs-vsctl -V ovs-vsctl (Open vSwitch) 2.12.0 DB Schema 8.0.0 Here is a screen shot of the PVE...
  4. J

    Virsh and OVS alternative for Security Onion on Proxmox

    Hi everyone, im trying to build a proxmox server with 3 nodes in it. First nodes for security onion,second nodes for honeyd and the third one for web server, Physical server and every nodes are using public IP , and i will do some penetration testing to webserver node from a private network and...
  5. G

    OpenvSwitch with IDS

    I am having a hard time figureing out how to set up proxmox to pass through traffic to a security oinon VM. I am using OVS and have 3 NICs bonded and sent to a bridge which is used as the normal interface and works great. I have a seperate NIC that is bridged to the VM from my switch with the...