OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: Monju0525 on February 17, 2024, 02:26:12 AM

Title: Suricata, Zenarmor , interfaces and vpn
Post by: Monju0525 on February 17, 2024, 02:26:12 AM
I am currently using a vpn via Wireguard. It works great.
Zenarmor is assigned to the lan. What should Suricata (IDS)  be assigned to : the wan or the wireguard_interface?
Under the IDS advanced mode, do I need to modify home networks? The helps says  "Networks to interpret as local", what does that mean?
Title: Re: Suricata, Zenarmor , interfaces and vpn
Post by: Melroy vd Berg on October 12, 2025, 04:37:38 PM
I know it's an old topic..

But I believe you should select your LAN interface only in Suricata. If not, correct me below via a reply comment.