OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: ruggerio on August 26, 2019, 06:58:40 am

Title: Suricata strange behaviour
Post by: ruggerio on August 26, 2019, 06:58:40 am
Since 19.7., i can no longer inspect more than one physical interface. My box has 3 active nics (wan, lan, dmz) which i'd like to inspect.

I already reset my box and restored, but i did not help. Whenever i activate IPS-Mode with wan only, it works. As soon as i also choose dmz and lan, it doesn't

I just tested with eicar. With wan only, i get the blocked message, adding dmz and lan, it just downloads *sigh*. And the logs do not tell me anything at all. Do i have the possibilty to set suricata in debug mode?