You are only browsing one thread in the discussion! All comments are available on the post page.

Return

MystikIncarnate ,

I didn't have to read far into the documentation of pi alert to find your issue. Scans and detection is done using ARP scans. ARP or address resolution protocol operates on layer 2. VLANs span layer 3 boundaries, so: layer 2 traffic does not traverse VLANs.

Additional scanning (by pi alert) is complimentary to the ARP scan. Which to me reads like ARP scans always need to work.

The easy solution is to use a trunk port into the system, and set up multiple VLAN sub interfaces on the NIC in the OS to handle each VLAN. Alternatively, give the VM multiple NICs, one for each VLAN you wish to scan.

The bottom line is that the pi alert system needs to have a direct network link into each network that it is trying to monitor.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • [email protected]
  • All magazines