Virsh and OVS alternative for Security Onion on Proxmox

Joshua_Yassar

New Member
Nov 26, 2017
4
0
1
27
Hi everyone, im trying to build a proxmox server with 3 nodes in it. First nodes for security onion,second nodes for honeyd and the third one for web server, Physical server and every nodes are using public IP , and i will do some penetration testing to webserver node from a private network and i want that security onion to detect that attack.. I created those 3 nodes with Linux Bridge on Proxmox, which caused data traffic(malicious ones that i want to detect) to webserver is not being monitored by security onion. I did some research and it seems i need to make some adjustment so that any traffic trying to come in/out to webserver node is being read/checked/monitored by security onion nodes first. My friend used Virsh to make a virtual private network among nodes in KVM (illustration on attached pic) so that any traffic sent to webserver node will need to go through security onion node. My problem is that it seems like Virsh is not supported on proxmox and i heard that OVS can do the trick but it's too complicated for me, anybody know any simpler alternative ways to make my data traffic going into webserver will have to go through security onion node first? Thanks,Sorry for my english :D

Goals to make traffic to service node will have to go through security onion node first.
Goals.png
My Simple topology
Simple Topology.png
 
Hi Denny on your configuration in that thread you have multiple eth(s) on your proxmox device and then make a bond for each of them. I only have 1 eth on my proxmox device, and i need to make both nodes(security onion and service server) have public ip. So am i going to make a linux bridge or ovs bridge? Here's my current setting.
 

Attachments

  • Capture.JPG
    Capture.JPG
    25.9 KB · Views: 12
  • Like
Reactions: Joshua_Yassar

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!