| View previous topic :: View next topic |
| Author |
Message |
chintaoui
Joined: 23 Jan 2007 Posts: 81 Location: France
|
Posted: Sun Mar 25, 2007 11:03 pm Post subject: Mac address with different IP range |
|
|
Sorry to repost but I have always a problem when I try to allow Mac adress for IP out of my honeyd range (i.e for virtual host on a different virtual network).
Always the same message
| Code: | | Template "test" is configured with ethernet address but there is no interface that can reach 10.1.0.22 |
|
|
| Back to top |
|
 |
laker8133
Joined: 06 Feb 2007 Posts: 32
|
Posted: Wed Mar 28, 2007 4:55 pm Post subject: hi |
|
|
David I believe the problem is either you haven't added a router to your honeyd config file or that you are trying to simulate your virtual computer across multiple networks that can see each other. Remember computer aren't suppose to have the same mac cards exactly.
I too am having this problem. If you do comment out the Mac line you will fine it works fine |
|
| Back to top |
|
 |
chintaoui
Joined: 23 Jan 2007 Posts: 81 Location: France
|
Posted: Wed Mar 28, 2007 11:16 pm Post subject: |
|
|
Hi Paul,
No I have many virtual routers in my honeyd conf file. I have many networks with differents IP range (networks on 10.0.0.0/8, 192.168.0.0/24, 128.96.17.0/24, etc ...).
All works (ping, services, etc ...), Adress mac assignation works for 128.96.17.0 (range of honeyd host).
What I don't understand is why is it working for ping, services, etc ... on each ip range and not for mac assignation ...
If networks can't see each other, I normally get nothing (no ping, etc ...) ...
Very lost about mac assignation
[EDIT] Paul had you ever tried to generate mac address for virtual host on other ip range ? If no could you try it please ? |
|
| Back to top |
|
 |
laker8133
Joined: 06 Feb 2007 Posts: 32
|
Posted: Thu Mar 29, 2007 5:29 am Post subject: david |
|
|
I will try that today David. Basically with the honeyd.conf laurence made for me. I had a couple of errors setting the same profile to a couple of different network domains. The way I'm going to solve this tho will be to Copy and paste the profile I want to emulate rename the profile name (ie pep6 or something like that), And only assign it with 1 ip address. Also Do remember. What you do for Honeyd, you also have to do with ARPD.
Take care David ,
Paul |
|
| Back to top |
|
 |
chintaoui
Joined: 23 Jan 2007 Posts: 81 Location: France
|
Posted: Thu Mar 29, 2007 6:21 am Post subject: |
|
|
I have no problem to assign the same profile to different IP range.
About arpd, it is like honeyd, it listen on my nic interface on all range. |
|
| Back to top |
|
 |
chintaoui
Joined: 23 Jan 2007 Posts: 81 Location: France
|
Posted: Tue Apr 03, 2007 4:58 am Post subject: |
|
|
Paul (aka Laker8133) get the same problem. Can others test too ?
Maybe Niels could add some informations about this please ? |
|
| Back to top |
|
 |
nielsprovos Site Admin
Joined: 01 Aug 2005 Posts: 79
|
Posted: Wed May 16, 2007 9:23 am Post subject: |
|
|
Mac addresses are link-layer mechanism. They only work for machines on the same network segment. The moment that a router gets in the way, the mac address is removed. The IP layer does not have MAC addresses.
Honeyd essentially tells you that you are trying to use MAC addresses, but that there is no ethernet interface for the IP range that you configured. I suppose I could just make that a warning instead of a failure.
Does this make more sense?
Niels. |
|
| Back to top |
|
 |
chintaoui
Joined: 23 Jan 2007 Posts: 81 Location: France
|
Posted: Wed May 16, 2007 2:42 pm Post subject: |
|
|
Thanks for answer. It's more clear now.
I think make a warning would be better.
So if I want mac addressing on virtual networks on ip range different from my honeyd host, the best way is to use several ethernet interface which run each honeyd ? |
|
| Back to top |
|
 |
nielsprovos Site Admin
Joined: 01 Aug 2005 Posts: 79
|
Posted: Sun May 27, 2007 11:45 pm Post subject: |
|
|
Chintaoui,
MAC addresses work only if you connect your virtual honeypots to your local network, otherwise, they cannot be seen. In particular, you cannot mix MAC addresses and virtual routes.
BTW, you probably want to upgrade to Honeyd 1.5c which I just released, it contains bug fixes in regards to the MAC code.
Niels. |
|
| Back to top |
|
 |
chintaoui
Joined: 23 Jan 2007 Posts: 81 Location: France
|
Posted: Mon May 28, 2007 12:10 pm Post subject: |
|
|
I use honeyd on my local network as a detection / prevention tool, that's why I'm very interested with MAC addressing. Connected to Internet I use a high interaction honeypot.
I will have a look at the new version tomorrow  |
|
| Back to top |
|
 |
boomika
Joined: 01 Jul 2010 Posts: 3
|
Posted: Thu Jul 01, 2010 9:36 pm Post subject: |
|
|
| Hi,Very nice post , I am new to this site ,for virtual host and website content related name ,you can approach this http://www.xnynz.com/ site ,in before here only i got my successful site ,also i pay just $1.99 per year , visit this site for more details.All the best. |
|
| Back to top |
|
 |
|