OPNsense Forum

Archive => 19.7 Legacy Series => Topic started by: xaz on January 15, 2020, 03:06:21 pm

Title: Questions on OPNsense capability
Post by: xaz on January 15, 2020, 03:06:21 pm
I am new to OPNsense and I am not sure if it is possible to achieve what I am looking for it to do. I have network at a location where I need OPNsense to function as the gateway/router for but on this network I also have some machines connected via wifi that i need monitor the traffic and I need for the following information to be gathered:


Is OPNsense capable of doing this?
Title: Re: Questions on OPNsense capability
Post by: fabian on January 15, 2020, 05:40:20 pm
You can temporary run a packet capture but for a permanent packet capture it would make sense to use a specialized appliance like moloch.

https://molo.ch/
Title: Re: Questions on OPNsense capability
Post by: xaz on January 15, 2020, 06:56:05 pm
You can temporary run a packet capture but for a permanent packet capture it would make sense to use a specialized appliance like moloch.

https://molo.ch/
would moloch run on separate hardware on on opnsense hardware?
Title: Re: Questions on OPNsense capability
Post by: Antaris on January 15, 2020, 08:48:13 pm
Hi xaz,

You can also take a look @ Sensei. It have very good session details and turns OPNsense in to the best NGFW so far. Even have a free version.

https://forum.opnsense.org/index.php?topic=9521.0 (https://forum.opnsense.org/index.php?topic=9521.0)
Title: Re: Questions on OPNsense capability
Post by: fabian on January 15, 2020, 08:53:47 pm
Moloch should and must not run on OPNsense. You need to add a mirror port on your Layer 2 devices to capture the traffic.