virtualbox settings network

802 views
Skip to first unread message

vxzdeff fasfv

unread,
Sep 6, 2013, 12:58:07 PM9/6/13
to securit...@googlegroups.com
what setting i need to make to network for security onion?

i mean i know i need 2 adapter which setting in the adapters i need to do?
1.NAT?
2.Bridged Adapter?
3.Internal Network?
and the Advanced setting
in the
Promiscuous Mode:
deny?
or
allow?

what i the installation i the start when i pick up the iso of security onion
which option i need to pick ?

1. live- boot the
2. xforcevens
3.install?
4.memtest?

Matt Gregory

unread,
Sep 6, 2013, 7:00:20 PM9/6/13
to securit...@googlegroups.com
There's this walk-through on the Security Onion wiki:  http://code.google.com/p/security-onion/wiki/IntroductionWalkthrough

I've also attached a VM configuration walk-through that covers settings setting up VirtualBox and ESXi, although I don't cover the actual installation of SO as the above link does.

Matt



--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at http://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/groups/opt_out.

SO_network_topology_20130409.pdf

vxzdeff fasfv

unread,
Sep 7, 2013, 4:57:16 AM9/7/13
to securit...@googlegroups.com
Why you guys don't make youtube video about installation ? :D

ok try this guide now.

vxzdeff fasfv

unread,
Sep 7, 2013, 5:19:15 AM9/7/13
to securit...@googlegroups.com
i want to change file snort.conf
192.168.0.0/24
i want modify to
192.168.1.0/24
how i can modify file?
i forgot how to do that,

Doug Burks

unread,
Sep 7, 2013, 7:54:28 AM9/7/13
to securit...@googlegroups.com
sudo leafpad /etc/nsm/HOSTNAME-INTERFACE/snort.conf
--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at http://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/groups/opt_out.


--
Doug Burks
http://securityonion.blogspot.com

vxzdeff fasfv

unread,
Sep 7, 2013, 9:30:37 AM9/7/13
to securit...@googlegroups.com
in virtulbox in network setting in adapter type which i need to pick up?

is work on my linux but not in my lan

vxzdeff fasfv

unread,
Sep 7, 2013, 9:53:43 AM9/7/13
to securit...@googlegroups.com
nevermind all work

what i did is 2 adapter with Bridged Adapter

in snort rules is there something i can add ?

i mean the snort rules works but is there something more simple rules?

like tcp scan .
malware alert
what i mean that the rules written ports scan etc.

Matt Gregory

unread,
Sep 7, 2013, 9:59:18 AM9/7/13
to securit...@googlegroups.com

I recommend "bridged networking" assuming you have the traffic you want to monitor going to the physical interface on your host machine.

On Sep 7, 2013 9:39 AM, "vxzdeff fasfv" <psdtoh...@gmail.com> wrote:
in virtulbox in network setting in adapter type which i need to pick up?

is work on my linux but not in my lan

Doug Burks

unread,
Sep 7, 2013, 9:40:21 PM9/7/13
to securit...@googlegroups.com
You have a few options for rulesets:
- Emerging Threats free ruleset
- Emerging Threats pro ruleset
- Sourcefire VRT ruleset
- Sourcefire Community ruleset
- combinations of the above

You can also add your own rules in /etc/nsm/rules/local.rules.
> --
> You received this message because you are subscribed to the Google Groups "security-onion" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
> To post to this group, send email to securit...@googlegroups.com.
> Visit this group at http://groups.google.com/group/security-onion.
> For more options, visit https://groups.google.com/groups/opt_out.



Reply all
Reply to author
Forward
0 new messages