Copy traffic to external IDS

  • Hi,

    I would like to connect an external IDS (securityonion) to pfsense and need to create something like a span port. I have a spare NIC and would like to copy all traffic between the LAN and WAN to this interface and hook this up to security onion.

    Is this possible? If so, can you give me a hint on how to configure this?


  • Bump ::)

    Also interested on how to forward to a dedicated "security onion" box.

  • Best to use a span port on your switch or a network tap. You can use the span feature of bridges to accomplish the same.

Log in to reply