I have securityonion connected to my router directly. My router has DDWRT on it (It is a TP-Link router), but I cannot find a VLAN tab anywhere.
I tried the following:
iptables -s 0.0.0.0 -t mangle -A PREROUTING -j TEE --gateway 192.168.1.147
iptables -s 0.0.0.0 -t mangle -A POSTROUTING -j TEE --gateway 192.168.1.147
where the 192.168.1.147 IP address was the management interface, since the other interface it created did not have an UP.
However, this did not appear to work. I tried doing curl
testmyids.com, but Snorby is constantly showing 0 alerts.
What else needs to be done to get securityonion up and running?
I have my modem, connected to my router, which has wireless.