Honeypots mailing list archives

Re: basic honeynet question


From: mat <mr () simla colostate edu>
Date: Fri, 07 Apr 2006 19:02:38 -0600

so i have my honeynet set up like this...

internet--|eth0  honeywall  eth1|--router--honeypot

the router obtains an IP address correctly, but i cannot access the internet with the honeypot box. i have disabled snort-inline so the packets should be sent. anyone have any ideas?




mr () simla colostate edu wrote:
im using the roo installation from www.honeynet.org and am having trouble understanding how the NIC cards are supposed to be set up. they say
* eth0 is the "Internet" or outside Interface
* eth1 is the LAN interface (Honeypot side)
* eth2 is the Management interface
* br0 is the virtual bridge interface (eth0 + eth1)

but i dont completly understand what that means.  is eth0 where the incoming connection comes, then eth1 is where the 
outbound packets are sent? also, do i need to set up a gateway before the honeypot? or can i user a router? im just 
really confused about how the physical networking is supposed to be done.  could someone give me some help?  thanks in 
advance


Current thread: