Honeypot Configuration with Firewalla Gold

Comments

4 comments

  • Avatar
    Firewalla

    Should work. This is somewhat like a quarantined segment. 

    As of how to run a honeypot, I assume you fully understand the risks and have the ability to manage it. 

    0
    Comment actions Permalink
  • Avatar
    Marc S

    Thank you for your prompt reply. I have a couple of questions for you. Currently the honeypot is sitting in a network/subnet that has multiple other hosts. From testing blocking rules I found out that firewalla rules do not in fact work if they are in the same network/subnet. My questions are:

    1) As this one host will be put in the DMZ, should it be compromised would an attacker have access to all the other hosts in that subnet? 

    2) Is firewalla able to detect malicious activity such as port scanning from this host to other hosts in the same subnet and/or other subnets? 

    Thank again!

    Marc 

    0
    Comment actions Permalink
  • Avatar
    James Willhoite

    I run Mysterium. I have a Firewalla Gold. I set up a new VLAN network just for this one device. Open the required ports to point to the computer (actually a VM) and turned monitoring off. Set rules that the entire network is not allowed to talk to any other network. and set up DNS to point to google. Seems to work just fine for me. 

    1
    Comment actions Permalink
  • Avatar
    Marc S

    Thanks James. ill give it a go :)

    0
    Comment actions Permalink

Please sign in to leave a comment.