-
Version2.4.110 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeEval Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU4 RAM16 Storage for /131Gb Storage for /nsm299Gb Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailPhysical host. No traffic coming in:
Everything i do on or with the onion host i see in the UI, however, i don't see any other traffic. For example, Host Overview and Connections seen by Zeek and Surikata dashboards are empty. BTW, i do have traffic on this interface: Output of No traffic on bond0 (might be expected, might not. Looking for feedback). Tip Output of
Output of
Output of
Tip Found this in the suricata stats:
Not sure what i forgot to configure. any ideas where to look? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 4 comments 2 replies
-
What does |
Beta Was this translation helpful? Give feedback.
-
I think i found something here. When i look in the Administration/Configuration i see Strelka, Zeek and Suricata (and Stenographer) as Enabled: false. Defaults are also false. Is it supposed to be like that? Because https://onion/docs/architecture.html#architecture tells me that those components take care of the packet capture and decoding. Maybe i have not gone through some post-installation configuration process? |
Beta Was this translation helpful? Give feedback.
-
Went through sosetup.log and saw this as well:
The journey continues.....
I start to think that, because enp0s20u2u3i5 is in monitor mode, it cannot be added to the bond. Am i wrong?
My thinking is that both answers needs to be a "yes", but i just want to be sure. |
Beta Was this translation helpful? Give feedback.
-
SOLVED IT!! bond0 was configured for an MTU of 9000 which my monitor interface cannot handle. Changed |
Beta Was this translation helpful? Give feedback.
SOLVED IT!!
(well, got it working)
bond0 was configured for an MTU of 9000 which my monitor interface cannot handle. Changed
mtu=9000
tomtu=1500
in/etc/NetworkManager/system-connections/bond0.nmconnection
, rannmcli connection down bond0
andnmcli connection up bond0
and i see traffic in my dashboard now.