Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - techadmin

#1
We are using OPNsense + Suricata at several sites and would like to transfer the Suricata rule settings made at the main site to all other sites automatically (e.g. via SSH).

(specifically the configuration "Services" -> "Intrusion Detection" -> "Policy" -> "Rule adjustments" in the web interface).

In /usr/local/etc/suricata/rules.config you will find exactly this information, but it is not sufficient to simply transfer this file to the other FWs via SSH. In the web interface (above path) the configuration from the inserted rules.config is not displayed even after a Suricata service restart.

Is it still necessary to read in the rules.config manually via a Suricata command?
#2
General Discussion / Re: Rule Separators
January 18, 2022, 11:47:59 AM
+1 Would love to see this feature, as I was used to it when using Fortigate. Even something fairly simple like pfSense did would do the job for me. I would also throw 20.- euros into the pot :)