VMware Cloud Community
seaeric
Contributor
Contributor

ESXi 6.5 & Security Onion

I am using the free version of ESXi 6.5. I've installed Security Onion. I have two physical Nic's on my ESXi server. Is there a way to configure ESXi to monitor traffic on my second NIC? I have two virtual switches connected to each NIC. I created separate port groups attached to each virtual switch. I have Security Onion connected to each port group/virtual switch. Under security I've allowed promiscuous mode. Unfortunately I can't see non-broadcast traffic on the monitored network. I have a network tap connecting the physical NIC to the network I want to monitor. I used Wireshark to verify the tap is working. Any ideas would be appreciated!

Reply
0 Kudos
0 Replies