Security Onion newb. Planned network diagram OK?

416 views
Skip to first unread message

Nick Whittome

unread,
Aug 12, 2015, 2:53:19 PM8/12/15
to security-onion
Hi

Planning my deployment of Security Onion at home and have prepared the attached diagram. Does this look right?

I don't have the wired router yet. Is there no alternative to this or do I have to buy one? Can I use just the existing wireless router (which I would change to a wireless AP in the diag) and the Dualcomm tap switch?

thanks for any feedback!
Security Onion network map diag.png

Wes

unread,
Aug 12, 2015, 3:50:19 PM8/12/15
to security-onion

Tri0x

unread,
Aug 12, 2015, 10:03:49 PM8/12/15
to security-onion
So long as nothing else is using your router as its connection point, it should work.

What do you plan to use for a tap?

All of your wireless devices will connect back to the AP, which will connect to the tap/switch and will be caught by SO.

Maybe my diagram will help.

Tri0x

so-capture.png

Nick Whittome

unread,
Aug 13, 2015, 10:52:58 AM8/13/15
to security-onion

Tony Carter

unread,
Aug 13, 2015, 2:11:30 PM8/13/15
to security-onion
This may be obvious but if your Wireless AP is operating in bridge mode and your router is providing DHCP then you'll see the IPs of devices behind it, otherwise you only see the AP's wan side IP for most traffic. Also, You will not see traffic between devices behind the AP.

HTH,
Tony

Tri0x

unread,
Aug 13, 2015, 7:20:18 PM8/13/15
to security-onion
On Thursday, August 13, 2015 at 10:52:58 AM UTC-4, Nick Whittome wrote:
> Dualcomm DSCW-1005
>
> http://dual-comm.com/port-mirroring-LAN_switch.htm

As I showed in my diagram, anything inside the red rectangle, going out to the Internet will get captured in the mirror port. Any port to port communication in the red rectangle will not be captured.

Are you using an AP or a router for your wireless access?

Tri0x

Nick Whittome

unread,
Aug 14, 2015, 10:02:01 AM8/14/15
to security-onion

Thanks for the info. It's a wireless router that I will put into AP mode. See screenshot

ap.png

Tri0x

unread,
Aug 15, 2015, 8:16:30 AM8/15/15
to security-onion
That should work fine. Make sure to give it a static IP for easy of troubleshooting.

I have a router working as an AP as well. I have not tested capturing wireless yet, but I expect no issues.

Hope this helps,

Tri0x

Reply all
Reply to author
Forward
0 new messages