Using Gigamon G-TAP A Series with SO

161 views
Skip to first unread message

KiwiNewbie

unread,
Jul 18, 2016, 7:20:46 PM7/18/16
to security-onion
Hello,

I am thinking about using the Gigamon G-TAP A Series with SecurityOnion however I do not know how this will work with SO. The TAP does not seem to provide aggregation of packets (full-duplex?) so I guess I need two NICs on the server running SO to match the two monitoring ports on the TAP..

If this is the case then how do you configure SO using Snort and BRO to monitor both NICs? It would be amazing if Snort and BRO can be smart enough to merge both NIC's data!

https://www.gigamon.com/products/g-tap-a-series

Cheers

Kiwi!

Wes

unread,
Jul 18, 2016, 7:47:49 PM7/18/16
to security-onion

KiwiNewbie

unread,
Jul 18, 2016, 7:58:29 PM7/18/16
to security-onion

Thank you Wes.

I also located this thread and the following recommendation - https://groups.google.com/forum/#!searchin/security-onion/tap/security-onion/pVm2cKePkNM/PifD3uhHZEEJ

"The solution for this is simple really. Before running sosetup, simply create a bridge interface with both NICs in it. This will combine RX and TX from the tap and keep it as a single interface presented to Snort etc.
This way you won't run into throughput problems that you would with an agg tap or a port span."

Reply all
Reply to author
Forward
0 new messages