Skip to content

IDH firewall issues? Can't reach honeypot services at all #9236

Locked Answered by defensivedepth
kingtriumph asked this question in Q&A
Discussion options

You must be logged in to vote

Are you using the ISO or Network install? Is this Centos or Ubuntu?


The [documentation for the IDH node](https://docs.securityonion.net/en/2.3/idh.html#idh) says you can run iptables commands from the IDH node itself to make firewall changes on the IDH ndoe.

You should not be manually editing firewall files or running iptables commands except for the one specific situation that the linked documentation makes note of: If you changed the default port of an IDH service, it needs to be manually closed. Other than that, as the docs state, use the default & minion sls file to customize ports, services etc.

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@kingtriumph
Comment options

@kingtriumph
Comment options

@defensivedepth
Comment options

@kingtriumph
Comment options

@defensivedepth
Comment options

Answer selected by kingtriumph
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants