snort

  1. M

    Setting up NIDS in VE, where put it in architecure and how redirect all trafic from/to Snort/Suricata

    Hello all, I want deploy snort in my VE, but i wounder what is the beast approach to do that. First idea is deploy vm with snort or something similar like suricata, but the real problem is ... how to redirect all traffic from NIC, VE from/to snort. I imagine it like this: vmbrX <-->...
  2. J

    Open vSwitch Port Mirror problem (SNORT/ZEEK/Security Onion)

    A fresh install of proxmox 6.2-10. I am trying to configure port mirroring with open vswitch. I installed open vswitch via apt install openvswitch-switch. I am running version 2.12 root@pve:~# ovs-vsctl -V ovs-vsctl (Open vSwitch) 2.12.0 DB Schema 8.0.0 Here is a screen shot of the PVE...
  3. I

    Problem with Snort and Port-Mirroring

    Hi there, first time poster here, nice to meet you all. We are trying to run Snort as an NIDS in a Container on our Proxmox. We have dedicated NICs on our server for each container (theoretically) and a Cisco 3750-Series Switch that is connected to a different Switch (which we can't manage)...
  4. G

    OpenvSwitch with IDS

    I am having a hard time figureing out how to set up proxmox to pass through traffic to a security oinon VM. I am using OVS and have 3 NICs bonded and sent to a bridge which is used as the normal interface and works great. I have a seperate NIC that is bridged to the VM from my switch with the...