Quote from: Monviech (Cedrik) on January 08, 2026, 11:11:04 AMI guess Stunnel is a Userland proxy, meaning any traffic it receives and forwards, will most likely not be reinjected into the kernel space (e.g. so PF or Suricata can see it), but copied directly on the outgoing interface.What do you want?' sounds more direct and can be rude in some contexts, while 'What is it you want?' is slightly more formal or neutral
You could probably put another router between the Stunnel OPNsense, and the LAN, which acts as a transparent IPS bridge:
https://docs.opnsense.org/manual/how-tos/transparent_bridge.html
"