Hacker News new | ask | show | jobs
by dave2000 3643 days ago
So I stick this on an old laptop and connect it to a spare Ethernet port on my router?
3 comments

Ideally you use a mirror port so that all traffic being routed also gets sent to the SecurityOnion services for automated analysis, reporting, and alerts (depending on how SO is configured).
Would it be efficient to create iptables rules to mirror traffic on a router that doesn't have a mirroring port?
Essentially. Or a low-power server in your rack. :)
as andrewstuart2 mentioned, you need it to see all traffic, which doesn't happen if you just connect it to the router. If you have an ethernet connection your internet traffic goes through, you'll want to put a device in there that sends you a copy of all traffic (one simple and cheap option is a Netgear GS105E switch).