So normally when adding an IDS (or in this case SO) to a network, as long as their switch supports it, I've always mirrored all ports to the IDS. However, a new client has all Ubiquiti Unifi hardware, brand new, and I was surprised to learn at their price point, it appears to only allow 1 port to be mirrored per switch -_-
That being said, is/has anyone else been using Ubiquiti, if so, was there any way around this? Or a suggested setup?
At this point, my thoughts are:
- The switches are daisy chained so I really only need to monitor the ingress/egress port on each switch.
- However, the main switch has multiple items such as servers, firewall, etc going in to it. Due to that, I was going to mirror the servers via vmware vnet, and probably have to put the firewall into a small 4 port switch that supports mirroring. Seems silly :\
Open to any thoughts and suggestions! Thanks.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.
To post to this group, send email to security-onion@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.