Re: Port Mirroring
James Ladd via Snort-users <[email protected]> Fri, 8 Mar 2024 01:53:14 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <PH7PR10MB64818502608309E9A8E82DB5FB272@PH7PR10MB6481.namprd10.prod.outlook.com> |
You would have to split one of the 2 nics away from the port group and dedicate the network port to the vm but then you will lose your redundant link. You can also I believe add a second virtual nick and set it for promiscuous mode in VMware but you will only see traffic spanning the v switch you will not see any additional traffic that goes over your physical switch. Personally I would recommend a dedicated box with 2 nics for this. You can maybe do it on one of those nuc type box’s that have dual nics a pie might not have enough power depending on the amount of traffic you have. If you want an awesome open source siem that used snort or suricata you should check out security onion Thanks, James ________________________________ From: Paul Giovanni <[email protected]> Sent: Thursday, March 7, 2024 7:23:39 PM To: James Ladd <[email protected]>; [email protected] <[email protected]> Subject: RE: Port Mirroring We have 3 ports on the back of the server. It seems like one of them is for IDRAC (integrated dell remote access controller.. basically remote management). The other two seem to be on one card, serving as a single switch. See image below: [cid:[email protected]] Am I able to use vmnic0 or vmnic1 for this purpose? Or would be need to buy a separate NIC to plugin to a PCIe port? If not I’ll probably just end up buying a raspberry pi to have a “snort in a box” Paul Giovanni IT Project Manager Edison, NJ<https://goo.gl/alXFy5> P: <tel:7329855000> (732) 985-5000<tel:7329855000> Gloucester City, NJ<https://goo.gl/PgMNnW> P: (856) 212-0050<tel:8562120050> [Facebook]<https://www.facebook.com/RaritanGroup/> [Instagram]<https://www.instagram.com/raritangroup/> [LinkedIn]<https://www.linkedin.com/company/raritan-group> [www.RaritanGroup.com]<http://www.raritangroup.com/> From: James Ladd <[email protected]> Sent: Thursday, March 7, 2024 6:30 PM To: Paul Giovanni <[email protected]>; [email protected] Subject: Re: Port Mirroring You don't often get email from [email protected]<mailto:[email protected]>. Learn why this is important<https://aka.ms/LearnAboutSenderIdentification> If your doing this on a vm in VMware you will want to pass a secondary dedicated Nic thru to that vm and set it for promiscuous mode. Then plug your mirror port from your switch into that Nic. Thanks, James ________________________________ From: Snort-users <[email protected]<mailto:[email protected]>> on behalf of Paul Giovanni <[email protected]<mailto:[email protected]>> Sent: Tuesday, March 5, 2024 1:10:54 PM To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>> Subject: [Snort-users] Port Mirroring All, I have a managed switch connected to my fire wall that I can port mirror from. However, I’m unsure where to plug the mirrored port in. Do I plug it right into my ESXI host. This host is hosting the VM that’s running snort. Thanks, Paul Giovanni IT Project Manager Edison, NJ<https://urldefense.proofpoint.com/v2/url?u=https-3A__goo.gl_alXFy5&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=WkEgvd3W36iY6YwGinG2GY5JiEa5PIxCpJWJmMpZorLW7Zj6bVev8BYuQ7cJw31y&s=uttQ47WQVfhDm26PbzETSVOFRZjA4klXbaHtYILfaU0&e=> P: <tel:7329855000> (732) 985-5000<tel:7329855000> Gloucester City, NJ<https://urldefense.proofpoint.com/v2/url?u=https-3A__goo.gl_PgMNnW&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=WkEgvd3W36iY6YwGinG2GY5JiEa5PIxCpJWJmMpZorLW7Zj6bVev8BYuQ7cJw31y&s=5SgmOYabTaD_WKo3tVgH8xozAYucCSbqon8dP7MoqZ8&e=> P: (856) 212-0050<tel:8562120050> [cid:[email protected]]<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.facebook.com_RaritanGroup_&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=WkEgvd3W36iY6YwGinG2GY5JiEa5PIxCpJWJmMpZorLW7Zj6bVev8BYuQ7cJw31y&s=8t3iRkTRgqf_BPg6kWH9sdFLeztGCcu0zbKRoyTr7T8&e=> [cid:[email protected]]<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.instagram.com_raritangroup_&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=WkEgvd3W36iY6YwGinG2GY5JiEa5PIxCpJWJmMpZorLW7Zj6bVev8BYuQ7cJw31y&s=OvXvkGMNHE2V2T3oQd3_AyzQY8Mra_OjEqzQVHQNEVw&e=> [cid:[email protected]]<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.linkedin.com_company_raritan-2Dgroup&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=WkEgvd3W36iY6YwGinG2GY5JiEa5PIxCpJWJmMpZorLW7Zj6bVev8BYuQ7cJw31y&s=fYJ59q4xZfwllRt2Tt0jEA_mjxNhXrS0_udvpOv3lBU&e=> [cid:[email protected]]<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.raritangroup.com_&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=WkEgvd3W36iY6YwGinG2GY5JiEa5PIxCpJWJmMpZorLW7Zj6bVev8BYuQ7cJw31y&s=-3OS-lSTFbhAy9N-l1QMNkQxdfZaNjmY4lgAl_0pykU&e=> ________________________________ This email has been scanned for spam and viruses. Click here<https://godaddy.cloud-protect.net/app/report_spam.php?mod_id=11&mod_option=logitem&report=1&type=easyspam&k=k1&payload=53616c7465645f5fde94027f7b022c15b8958e0496878c584985d60cd3bc98058aeb65e55a786ae3a664a552be3c42ef4df74871bf94e0cb061a9a839930864fcb7070a6c7ed3b33a481900f3d1e41ebd0c9175ac6d20762a40b8854585cf10240fafbb609c4229ced5a5f52aa59b5e1b04ad7383edef2c4aa2278148d256c73b446380953d8c2dd91d03584c78cc0bc01417addf0040f4cf82a02a9e9504107> to report this email as spam. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
image001.png
(image/png, 641 B) - not displayed
image002.png
(image/png, 905 B) - not displayed
image003.png
(image/png, 642 B) - not displayed
image004.jpg
(image/jpeg, 45.8 KB) - not displayed
image005.png
(image/png, 28.6 KB) - not displayed
image425010.png
(image/png, 641 B) - not displayed
image797543.png
(image/png, 905 B) - not displayed
image377939.png
(image/png, 642 B) - not displayed
image179891.jpg
(image/jpeg, 45.8 KB) - not displayed