Snort not picking up host of the virtual environment

311 views
Skip to first unread message

Aaron Smith

unread,
Oct 17, 2014, 11:56:16 PM10/17/14
to securit...@googlegroups.com
I am new to all of this and am just beginning to playg around with security onion so please bear with me.

I have got security onion up and running, snort.conf file is modified to be monitoring my private network of 192.168.1.0/24.

I have loaded onto a VMWare Workstation the following: Security Onion, Kali Linux, Ubuntu Desktop. All network adapters are set to bridged so all 3 virtual systems as well as my windows host are all on the 192.168.1.0/24 network.

Snort picks up the pings going between all the virtual systems as well as when I curl http://www.testmyids.com but does not pick up pings from my windows host system to any of the virtual systems or going to the testmyids.com website.

Why would this traffic not get picked up if its on the same network? Sorry if its an obvious answer, again I am new to all of this, including virtualization. Thanks.


Heine Lysemose

unread,
Oct 18, 2014, 7:36:55 AM10/18/14
to securit...@googlegroups.com

Hi

Have you set the bridged interface to allow promiscuous mode both virtual and host?

Regards,
Lysemose

--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at http://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.

Shane Castle

unread,
Oct 18, 2014, 9:18:11 AM10/18/14
to securit...@googlegroups.com

Aaron Smith

unread,
Oct 18, 2014, 4:38:36 PM10/18/14
to securit...@googlegroups.com
The NIC on the VM used for the sensor shows it is in promiscuous mode when i run ifconfig, I have not been able to figure out how to enable or even tell if my host NIC is in promiscuous mode.

A ping from any of my 3 VMs (all in bridged mode) to my host system gets picked up by the IDS, no pings from my Host to any of the 3 VMs gets picked up though.

Shane Castle

unread,
Oct 19, 2014, 3:02:16 AM10/19/14
to securit...@googlegroups.com
Um try this link instead: https://groups.google.com/forum/m/#!topic/security-onion/C8yqVl1u7WY

Only has direct application to VM Workstation but the concepts should be applicable to other VM setups.

Sent from my iPad

Heine Lysemose

unread,
Oct 20, 2014, 8:49:58 AM10/20/14
to securit...@googlegroups.com
Hi

In VirtualBox you can choose on your bridge network Not Allowed, Allow VMs, Allow All.You should choose the latter...
In don' know the settings in VMware Workstation.

Regards,
Lysemose
Reply all
Reply to author
Forward
0 new messages