-
Hi guys, I´m building a security lab on top of HyperV and I´m having issuess to see the traffic in the monitoring interface of SecOnion.
I´ve created a pfsense VM and connected it to all these vSwitches with this configuration: WAN (wan) -> hn0 -> v4/DHCP4: 192.168.1.124/24 Bridge0 has the Victim interface as member and Mirroring as span port. Then, I created the SecOnion VM attaching it to 2 vSwitches: SecOnionMGMT and Mirroring; Is there any missing configuration? Regards, Rodrigo |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
If you run tcpdump on the Security Onion monitoring interface and don't see any traffic, then the problem exists outside of Security Onion. |
Beta Was this translation helpful? Give feedback.
If you run tcpdump on the Security Onion monitoring interface and don't see any traffic, then the problem exists outside of Security Onion.