I've found myself super confused after reading documentation and trying to use AI to get the answer (which has done nothing but give conflicting responses).
When using "Divert" for my setup, I want traffic on both a parent interface and its associated VLAN inspected.
With other capture modes, like NETMAP, it's made very clear to only apply it to the parent interface with promiscuous mode enabled (which does not exist for Divert).
Divert is not as well documented, and a lot of the information out there gets confused with NETMAP (hence the AI problem). Should I set a divert rule on *both* parent and the VLAN interfaces, or only do the divert rule on the parent interface with a standard pass rule on the VLAN?
Will VLAN traffic be inspected twice if I do it on both, causing an unnecessary performance hit? Or does divert mode, without the promiscuous option, necessitate having separate rules for each interface?
EDIT: Example with documentation confusion - "Interfaces to protect. When in IPS mode, this needs to be real interfaces supporting netmap. (when using VLANs, enable IPS on the parent)"
https://docs.opnsense.org/manual/ips.html
If not using netmap because of the divert rule, then what?
When using "Divert" for my setup, I want traffic on both a parent interface and its associated VLAN inspected.
With other capture modes, like NETMAP, it's made very clear to only apply it to the parent interface with promiscuous mode enabled (which does not exist for Divert).
Divert is not as well documented, and a lot of the information out there gets confused with NETMAP (hence the AI problem). Should I set a divert rule on *both* parent and the VLAN interfaces, or only do the divert rule on the parent interface with a standard pass rule on the VLAN?
Will VLAN traffic be inspected twice if I do it on both, causing an unnecessary performance hit? Or does divert mode, without the promiscuous option, necessitate having separate rules for each interface?
EDIT: Example with documentation confusion - "Interfaces to protect. When in IPS mode, this needs to be real interfaces supporting netmap. (when using VLANs, enable IPS on the parent)"
https://docs.opnsense.org/manual/ips.html
If not using netmap because of the divert rule, then what?
"