I'm trying to set up SO in my home network to lab and see if I can monitor all ingress/egress traffic from my SOHO router. I don't have a switch with SPAN ports, or a network tap so I'm using OpenWRT in combination w/ iptables mirroring functionality via --tee.
My management interface on my SO VM is 192.168.1.100/24. I'm using the following iptables routes, added via SSL to OpenWRT, and verified in the status -> firewall web UI.
iptables -t mangle -A PREROUTING -d 192.168.1.0/24 -j TEE --gateway 192.168.1.100
iptables -t mangle -A POSTROUTING -s 192.168.1.0/24 -j TEE --gateway 192.168.1.100
OpenWRT says that it is indeed sending traffic on the .1 subnet to .100, however when I log into the SO machine and try to trigger IDS events from another machine on the subnet, nothing flags. I tried doing tcpdump to check traffic, and I'm not seeing any foreign traffic on the VM either. All I see are just DHCP requests.
Thoughts on what I might be doing wrong here? Appreciate any assistance!
Update 1/13/18 - Resolved the issue. The wireless card was having troubles with vmware & promisc mode. Once I swapped to a cable, I was able to see all inbound traffic from other hosts in the subnet!