OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: greffter on February 16, 2021, 07:03:15 PM

Title: First time user setup - which interfaces
Post by: greffter on February 16, 2021, 07:03:15 PM
I admit to being a little confused about which interfaces to place intrusion detection on.

Here is my network topology

6 Port Protectli box

All traffic is tagged in the switch and passed through the LAGG.

I believe I don't need intrusion detection on the WAN since it's completely locked down using firewall rules. I do want it on my internal network to ensure that nothing is compromised.

In the Intrusion Detection admin page in the interfaces dropdown I see the all the interfaces linked above AND I see em3, em4, em5 which are the physical ports that I have set in the LAGG. 

Should I be setting intrusion detection on the single interface named TRUNK and assume it can see all the traffic from the VLANS? Should it be set to the physical interfaces which comprise the LAGG?  or to the VLANS themselves?
Title: Re: First time user setup - which interfaces
Post by: lfirewall1243 on February 16, 2021, 10:04:45 PM
Normally on the physical interface for VLans

And enable the promiscuous mode

And don't forget to enable advanced config and add your local networks