Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
First time user setup - which interfaces
« previous
next »
Print
Pages: [
1
]
Author
Topic: First time user setup - which interfaces (Read 1631 times)
greffter
Newbie
Posts: 11
Karma: 2
First time user setup - which interfaces
«
on:
February 16, 2021, 07:03:15 pm »
I admit to being a little confused about which interfaces to place intrusion detection on.
Here is my network topology
6 Port Protectli box
2 Empty ports (LAN and OPT1) -
Lagg0 (named TRUNK) - 3 ports in LACP LAGG going to Cisco managed port in trunk mode-> 10.0.10.1/24
VLAN10 - HOME - 10.0.0.1/24
VLAN20 - GUEST - 10.0.20.1/24
VLAN30 - SERVERS - 10.0.30.1/24
All traffic is tagged in the switch and passed through the LAGG.
I believe I don't need intrusion detection on the WAN since it's completely locked down using firewall rules. I do want it on my internal network to ensure that nothing is compromised.
In the Intrusion Detection admin page in the interfaces dropdown I see the all the interfaces linked above AND I see em3, em4, em5 which are the physical ports that I have set in the LAGG.
Should I be setting intrusion detection on the single interface named TRUNK and assume it can see all the traffic from the VLANS? Should it be set to the physical interfaces which comprise the LAGG? or to the VLANS themselves?
Logged
lfirewall1243
Hero Member
Posts: 1386
Karma: 45
Re: First time user setup - which interfaces
«
Reply #1 on:
February 16, 2021, 10:04:45 pm »
Normally on the physical interface for VLans
And enable the promiscuous mode
And don't forget to enable advanced config and add your local networks
Logged
(Unoffial Community) OPNsense Telegram Group:
https://t.me/joinchat/0o9JuLUXRFpiNmJk
PM for paid support
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
First time user setup - which interfaces