Jump to content

TAPS Network Monitoring


G+_Tim Bentley
 Share

Recommended Posts

TAPS Network Monitoring

 

Using Security Onion as a monitoring solution with 3 NIC's . Two NICS are running in promiscuous mode connected to two Gigabit switches on different segments of the network.

Is this not the same as adding TAPS as I can see all the traffic passing through?

Link to comment
Share on other sites

Not quite the same thing.

 

Taps are just watching data flow through but typically can't change the data. Neither end knows the tap exists.

 

You basically have a router that monitors all the traffic flowing through it. Both sides can see your router and your Security Onion computer can inject or change data as it flows through.

 

If Security Onion can't keep up, you will probably slow down the transfer of data. If a tap can't keep up you'll lose the reading/logging of some data.

Link to comment
Share on other sites

Yup, I think I misunderstood the setup by thinking the Onion was the gateway between the two segments. I guess that's not how it works... Does Security Onion do ARP spoofing or something? I'm curious how it would be able to monitor all traffic on the switch. Now I'm curious and have to do more research ?

Link to comment
Share on other sites

 Share

×
×
  • Create New...