Saeed khan
unread,Jun 9, 2012, 8:23:47 AM6/9/12Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to security-onion
Hi,
We have different DMZ's and currently i have attached the IDS box
(only one NIC) on our DMZ Switch and enabled the SPAN and i can easily
see other ports traffic but as you know on enabling SPAN i can't
access the snorby interface, remotely etc.
I am just thinking to adding one more interface and snorby interface
access by eth0 and SPAN another NIC.
Is it possible? and if Yes then should i add one more IP address on
the 2nd NIC or what will be the eth1 configuration?
Here is the details of the existing NIC.
==============================================================================
auto lo
iface lo inet loopback
# OR if using STATIC IP instead of DHCP
auto eth0
iface eth0 inet static
address 172.20.4.253
gateway 172.20.4.1
netmask 255.255.255.0
network 172.20.4.0
broadcast 172.20.4.255
==============================================================================
I hope you understand, what exactly i meant.
Waiting for prompt reply.
Regards,
Saeed