Honeypots mailing list archives

Honeynet behind DSL router


From: "Sid" <TheSid () gmx net>
Date: Mon, 1 May 2006 12:45:51 +0200 (MEST)

Hello,

I tried to set up a virtual honeynet with the honeywall roo , but faced some
troubles in the end - sadly. The wall most likely quits working when loading
the HAL it seems, at least my CPU Usage goes up to 100 % for quite a long
while.. until i decide to either disconnect one bridge or shut off the
virtual guest system.

So I take it's probably some misconfiguration within the wall. I am
connected to internet with a DSL router. Behind there is a windows xp host
(I know, Linux might be better choice, but it should work with windows too I
hope ;-) ). Guest systems are the honeywall + several honeypots. 

The IP of the router is 192.168.2.1 . The host is 192.168.2.128 . The host
only IP adress of vmware is 192.168.2.40.

That's the currently given IP settings. The honeypot i set to IP
192.168.2.20 ... which would be the "honeynet subnet", the public ip address
for the honeypots (the actual IP i get from the ISP or the internal private
addresses ?) Does it have to be host only or bridged? And will the honeywall
be able to log all information?

I tried to set up the management interface too, set it to 192.168.2.41 - and
allowed the 40, 41 and 128 to it. I never was able to access the ssh
interface though. I start to feel stupid ;-)

The issue with the "menu" not popping up after the installation is also
known to me. Occurs with the newest roo it seems. The PATH is not being set
correctly. 
export PATH=$PATH:/sbin:/usr/sbin:/usr/local/sbin helps.. but i wonder why
it does not correctly work with the settings in the /etc/profile. There it
should do the pathmurge already ...

Ah.. to come to an end with my tons of questions:
Do I need to set up ICS on my LAN card of winxp? the dial-in to the ISP is
done by the router ...

Thanks for all the help in advance :)

-- 
GMX Produkte empfehlen und ganz einfach Geld verdienen!
Satte Provisionen für GMX Partner: http://www.gmx.net/de/go/partner


Current thread: