I'm pretty new to OSSIM so there might be obvious mistakes that I haven't taken into account.
First, let me explain what I want to do.
I have installed an OSSIM server with three nic cards.
One for management with ip 192.168.1.4
One for Log collection & Scanning with ip 192.168.1.5
One for network monitoring on promisc mode with port mirroring that receives data from all the 192.168.1.0/24 net
On alienvault-setup I configure them accordingly, activating netflow generator on port 555. After that I go to
Configuration - AlienVault components - Sensors
And check if it's activated the netflow or not, it is and by default it's on port 12000.
I activate my net, scan for assests, ids monitoring, etc. After that, I check the netflow tab and it works correctly.
so far, so good.
Now, problem arises when I try to do the same thing on a sensor.
I set up a sensor installation on a server that has two nic cards.
First Nic card has an IP withing the range of the server (so they can see each other and communicate)
Second nic card on promisc mode that receives data from a different net (10.10.1.0/24)
I configure the sensor on alienvault-setup telling that the second nic card monitors 10.10.1.0/24 and that the IP address
of the server and the framework is 192.168.1.4, I activate netflow on alienvault-setup again with 555 as port I then proceed to check the sensor on the framework and activate netflow
and assign the port 12000, so sensor is detected and added to the server, I then proceed to scan assets, etc.
And well, It never show anything on the netflow framework, I tried following this guide:http://hummy.wikidot.com/netflows
But nothing, I did checked that traffic is going to the server on port 555 from the sensor, but nothing shows up
Can somebody give me some pointers?