IDS / IPS for proxmox in vm (suricata or securityonion)

houbidoo

Renowned Member
Mar 16, 2015
13
1
68
Hello guys,

i am relativly new to proxmox and just installed and configured my host and virtual mashines.

Host: dell r410, 2x xeon cpu, 12 GB ddr3, raid 1, Proxmox 3.4
Virtual mashines: 7x openvz with Debian wheezy
Running the iptables firewall

What i want to do:
I like to have one openvz vm running an IDS / IPS (for me IDS Funktion would be enough) which monitores the traffic oft the whole node (host and all virtual mashines).

Is it possible?
What network configurations do i have to make?
Last question: if i run an IPS do i nees to have iptables do the firewall work, vor will the IPS do everything for me? (Background: if iptables Blocks traffic i will not See it in IDS)
 
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!