In my setup I have deployed a sensor. Currently it is sitting on my LAN with the MHN server. When I move it to the DMZ it changes IP. How do I tell the MHN server this?
Thanks
/klaus
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-net...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/e35d1513-75f4-4d03-a3ce-71294fbb3ce1%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
MHN uses the architecture, protocols, and software defined by the honeynet project for communications between the server and the honeypots. I believe the biggest reason why the architecture is the way it is is for OPSEC and simplicity of management. If all the sensors listened on a port used for management control it would be trivial to fingerprint the sensors. It also allows the honeypots to be moved (DHCP) without having the management overhead of having to track this.When you move your honeypot sensor, you should not have to update MHN. Data will continue to flow properly.Thanks,--Jason
On Sun, Sep 13, 2015 at 9:08 AM, <kl...@agnoletti.dk> wrote:
This is an issue for me too. I want the sensor itself to sit in a DMZ which is totally locked down - no access to anything. So I don`t understand why this scenario hasn't been implemented (at least in my mind) properly. Instead of the sensor connecting to the MHN server, I would want it the other way around; the MHN server polling the sensors. After all, this is a security product implemented for the most part by security aware people. I don't think I am the only one that doesn't want the honeypot to be a threat to my overall network security.
In my setup I have deployed a sensor. Currently it is sitting on my LAN with the MHN server. When I move it to the DMZ it changes IP. How do I tell the MHN server this?
Thanks
/klaus
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/e35d1513-75f4-4d03-a3ce-71294fbb3ce1%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.