[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-users] Snort monitoring of Xen guests



Hi all,

From another post on this list, it seems that the only way to monitor all traffic to guests in a host is to bind to the peth interface that is bound to the bridge that serves the guests. Is this the only way of doing it? Ideally, I'd like to have one guest running Snort that monitors everything else.

I've tried using tcpdump to monitor traffic on various interfaces, but I've never had a completely satisfactory result. On guest interfaces, I can only see traffic for that guest (this seems to be a feature); on Dom0 I get a long pause (10-20s), then I start to see packets. Also, with the Dom0 monitoring, I can only seem to see traffic on the peth interface. Binding to vif0.0 gives me nothing interesting.

At the moment, I'm researching the use of tc (traffic control) to mirror traffic to another device to get the effect of a monitor port on the xen-bridge.

Any help on this would be very appreciated.

Mark C.

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.