Monkey.org Developments
Honeyd Discussion Forums :: View topic - Mac address with different IP range

Support Honeyd

Search:
Keywords:

Search Amazon
Honeyd Discussion Forums
Everything relating to Honeyd
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Mac address with different IP range

 
Post new topic   Reply to topic    Honeyd Discussion Forums Forum Index -> General
View previous topic :: View next topic  
Author Message
chintaoui



Joined: 23 Jan 2007
Posts: 81
Location: France

PostPosted: Sun Mar 25, 2007 11:03 pm    Post subject: Mac address with different IP range Reply with quote

Sorry to repost but I have always a problem when I try to allow Mac adress for IP out of my honeyd range (i.e for virtual host on a different virtual network).

Always the same message

Code:
Template "test" is configured with ethernet address but there is no interface that can reach 10.1.0.22
Back to top
View user's profile Send private message
laker8133



Joined: 06 Feb 2007
Posts: 32

PostPosted: Wed Mar 28, 2007 4:55 pm    Post subject: hi Reply with quote

David I believe the problem is either you haven't added a router to your honeyd config file or that you are trying to simulate your virtual computer across multiple networks that can see each other. Remember computer aren't suppose to have the same mac cards exactly.

I too am having this problem. If you do comment out the Mac line you will fine it works fine
Back to top
View user's profile Send private message
chintaoui



Joined: 23 Jan 2007
Posts: 81
Location: France

PostPosted: Wed Mar 28, 2007 11:16 pm    Post subject: Reply with quote

Hi Paul,

No I have many virtual routers in my honeyd conf file. I have many networks with differents IP range (networks on 10.0.0.0/8, 192.168.0.0/24, 128.96.17.0/24, etc ...).

All works (ping, services, etc ...), Adress mac assignation works for 128.96.17.0 (range of honeyd host).

What I don't understand is why is it working for ping, services, etc ... on each ip range and not for mac assignation ...

If networks can't see each other, I normally get nothing (no ping, etc ...) ...

Very lost about mac assignation

[EDIT] Paul had you ever tried to generate mac address for virtual host on other ip range ? If no could you try it please ?
Back to top
View user's profile Send private message
laker8133



Joined: 06 Feb 2007
Posts: 32

PostPosted: Thu Mar 29, 2007 5:29 am    Post subject: david Reply with quote

I will try that today David. Basically with the honeyd.conf laurence made for me. I had a couple of errors setting the same profile to a couple of different network domains. The way I'm going to solve this tho will be to Copy and paste the profile I want to emulate rename the profile name (ie pep6 or something like that), And only assign it with 1 ip address. Also Do remember. What you do for Honeyd, you also have to do with ARPD.


Take care David ,

Paul
Back to top
View user's profile Send private message
chintaoui



Joined: 23 Jan 2007
Posts: 81
Location: France

PostPosted: Thu Mar 29, 2007 6:21 am    Post subject: Reply with quote

I have no problem to assign the same profile to different IP range.

About arpd, it is like honeyd, it listen on my nic interface on all range.
Back to top
View user's profile Send private message
chintaoui



Joined: 23 Jan 2007
Posts: 81
Location: France

PostPosted: Tue Apr 03, 2007 4:58 am    Post subject: Reply with quote

Paul (aka Laker8133) get the same problem. Can others test too ?

Maybe Niels could add some informations about this please ?
Back to top
View user's profile Send private message
nielsprovos
Site Admin


Joined: 01 Aug 2005
Posts: 79

PostPosted: Wed May 16, 2007 9:23 am    Post subject: Reply with quote

Mac addresses are link-layer mechanism. They only work for machines on the same network segment. The moment that a router gets in the way, the mac address is removed. The IP layer does not have MAC addresses.

Honeyd essentially tells you that you are trying to use MAC addresses, but that there is no ethernet interface for the IP range that you configured. I suppose I could just make that a warning instead of a failure.

Does this make more sense?

Niels.
Back to top
View user's profile Send private message
chintaoui



Joined: 23 Jan 2007
Posts: 81
Location: France

PostPosted: Wed May 16, 2007 2:42 pm    Post subject: Reply with quote

Thanks for answer. It's more clear now.

I think make a warning would be better.

So if I want mac addressing on virtual networks on ip range different from my honeyd host, the best way is to use several ethernet interface which run each honeyd ?
Back to top
View user's profile Send private message
nielsprovos
Site Admin


Joined: 01 Aug 2005
Posts: 79

PostPosted: Sun May 27, 2007 11:45 pm    Post subject: Reply with quote

Chintaoui,

MAC addresses work only if you connect your virtual honeypots to your local network, otherwise, they cannot be seen. In particular, you cannot mix MAC addresses and virtual routes.

BTW, you probably want to upgrade to Honeyd 1.5c which I just released, it contains bug fixes in regards to the MAC code.

Niels.
Back to top
View user's profile Send private message
chintaoui



Joined: 23 Jan 2007
Posts: 81
Location: France

PostPosted: Mon May 28, 2007 12:10 pm    Post subject: Reply with quote

I use honeyd on my local network as a detection / prevention tool, that's why I'm very interested with MAC addressing. Connected to Internet I use a high interaction honeypot.

I will have a look at the new version tomorrow Wink
Back to top
View user's profile Send private message
boomika



Joined: 01 Jul 2010
Posts: 3

PostPosted: Thu Jul 01, 2010 9:36 pm    Post subject: Reply with quote

Hi,Very nice post , I am new to this site ,for virtual host and website content related name ,you can approach this http://www.xnynz.com/ site ,in before here only i got my successful site ,also i pay just $1.99 per year , visit this site for more details.All the best.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Honeyd Discussion Forums Forum Index -> General All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB 2.0.9 © 2001, 2002 phpBB Group