Skip to content
Discussion options

You must be logged in to vote

Resolved. Firewall issue.
The NetFlow integration was working. OPNsense was exporting valid NetFlow. The Security Onion Fleet-managed agentbeat input was capable of decoding and indexing the packets. What was missing was allowing the OPNsense exporter through Security Onion’s host firewall on UDP/2055. Doing this from the SOC GUI did not work, had to use the command line.

This was confusing because tcpdump seeing UDP/2055 on the interface was not enough. The packet still had to pass the Security Onion host firewall before agentbeat could receive it.

Live and learn.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by cm-ops
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
1 participant