Setting up SPAN Port for Security Analytics
-
Good Afternoon,
I have gone through a lot of the different threads on this, and still trying to figure out the best eway to do this, any help is greatly appreciated.
I have a Security Analytic box (VM) in Workstation (I know my 1st challenge), I also have my PFSense router and many other systems. I might be missing something simple, but I need to create a span port, that one of my VM sees. I have created the Bridge, added members, created a separate OPT interface with virtual NIC, copied the mac addr, everything to somehow get this mirror port seen by the Virtual Analytic system. Its just seeing a trickle of packets over the network so far.
Is there something I'm missing, should i stand up another PFsense router, and place the Analytic system in the middle, if so, any advice for doing this…
Thanks,
-
A span port would be done on your switch.. Not on pfsense with a bridge.