User Tools

Site Tools


articles

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
articles [2018/10/03 10:38]
veera [Administration Tips]
articles [2019/07/13 12:45] (current)
veera [Netflow tunneling]
Line 9: Line 9:
  
 [[hardware:​erspan|Configuring ERSPAN for packet capture into Network Security Monitoring tools]] [[hardware:​erspan|Configuring ERSPAN for packet capture into Network Security Monitoring tools]]
 +
 +
 +==== Netflow tunneling ====
 +
 +Tunneling Netflow to a remote Trisul involves preserving the original IP address of the switch/​router. We describe three methods to achieve it, NAT, GRE, and Shim Tunnels. ​
 +
 +[[hardware:​gatewaynetflow|Using NAT on gateway to send Netflow to remote Trisul]]
 +
 +[[hardware:​gretunnel|Using GRE Tunnel to send Netflow to a remote Trisul]]
 +
 +[[hardware:​shimtunnel|Using a Shim Tunnel to send Netflow to a remote Trisul]]
 +
 +[[hardware:​shimtunnelintro|Use a Shim Tunnel when you cant use GRE or NAT ]]
 +
 ===== Docker ===== ===== Docker =====
  
Line 57: Line 71:
  
 [[ids:​snort|Connecting Trisul to Snort with Emerging Threats Rules ]] [[ids:​snort|Connecting Trisul to Snort with Emerging Threats Rules ]]
 +
 +
 +[[ids:​snort3|Connecting Trisul to Snort3]]
  
  
Line 86: Line 103:
 [[monit:​monitoring_and_maintain_trisul_process|How to use Monit to keep an eye on Trisul processes and restart them if necessary]] [[monit:​monitoring_and_maintain_trisul_process|How to use Monit to keep an eye on Trisul processes and restart them if necessary]]
  
 +[[admin:​ha|Primary and backup configuration]]
  
 +[[admin:​udpserver|Check if UDP packets are received]]
 +===== External links =====
 +[[Get google api key: Get Google API Key]]
  
- 
-===== External links ===== 
 [[Other links: external_links]] [[Other links: external_links]]
  
articles.1538563120.txt.gz · Last modified: 2018/10/03 10:38 by veera