Quote from: Monviech (Cedrik) on November 08, 2025, 09:37:18 PMIPS on layer 2 only works if the host can actually intercept the traffic "in line", meaning there is a transparent filtering bridge configuration.Thanks. I suspected that a filtering bridge with two physical network interfaces would be necessary. I will put it behind my perimeter OPNsense firewall so that the Suricata bridge is the first in-line feeding the DMZ network where the publicly accessible services are located. The internal OPNsense firewall/router will be next with the ELK stack located on one of it's internal networks.
I am not certain at the moment if it is worth having a third interface on the Suricata IPS to isolate logstash traffic. I keep all my IPMI, SNMP and syslog on an isolated VLAN that has no internet connectivity.
"