[qubes-users] How To Set Up Traffic Mirroring To Security Onion

2020-04-29 Thread 'Zsolt Bicskey' via qubes-users
I am building a lab inside QubesOS. I have two gateways, two firewalls. Behind the pentest-firewall I want all machines to see each other. Since I have both Win and Linux machines and for simplicity's sake I am doing this from the firewall. On top of this I have a Security Onion running to capt

Re: [qubes-users] How To Set Up Traffic Mirroring To Security Onion

2020-04-30 Thread Aret
Hi, Duknow if make actual sense on Qubes, but i used the following successfully on XenServer/XCP-ng, inbound traffic is not visible to SecurityOnion otherwise as originally targetting the tapped network from my understanding: https://blog.rootshell.be/2013/09/09/xenserver-port-mirroring/ Ho

Re: [qubes-users] How To Set Up Traffic Mirroring To Security Onion

2020-05-01 Thread 'Zsolt Bicskey' via qubes-users
Duknow if make actual sense on Qubes, but i used the following successfully on XenServer/XCP-ng, inbound traffic is not visible to SecurityOnion otherwise as originally targetting the tapped network from my understanding: > https://blog.rootshell.be/2013/09/09/xenserver-port-mirroring/ > > Hop

Re: [qubes-users] How To Set Up Traffic Mirroring To Security Onion

2020-05-04 Thread 'Zsolt Bicskey' via qubes-users
Does anyone have some creative ideas how I could mirror all traffic on this subnet into the SecurityOnion HVM? -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qu