Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - romjan

#1
26.1 Series / Re: Suricata - Divert (IPS)
Today at 07:53:00 AM
Thanks for helping! I have a "static IP ISP provider modem, no PPPoE. Q-Feeds ist working, but i can't see any dropping from suricata in suricta logonly:
2026-03-26T00:00:23Noticesuricata[100882] <Notice> -- rule reload starting
2026-03-25T21:28:34Noticesuricata[100882] <Notice> -- Threads created -> W: 8 FM: 1 FR: 1 Engine started.
2026-03-25T21:28:18Noticesuricata[100882] <Notice> -- Syslog: facility local5, level Info, ident suricata
2026-03-25T21:28:18Noticesuricata[107591] <Notice> -- This is Suricata version 8.0.4 RELEASE running in SYSTEM mode
2026-03-25T21:28:17Noticesuricata[109386] <Notice> -- (W-8000) Verdict: Accepted 0, Dropped 0
2026-03-25T21:28:17Noticesuricata[109386] <Notice> -- (W-8000) Treated: Pkts 723, Bytes 35427, Errors 0
2026-03-25T21:28:17Noticesuricata[109385] <Notice> -- (W-8000) Verdict: Accepted 0, Dropped 0
2026-03-25T21:28:17Noticesuricata[109385] <Notice> -- (W-8000) Treated: Pkts 0, Bytes 0, Errors 0
2026-03-25T21:28:17Noticesuricata[109384] <Notice> -- (W-8000) Verdict: Accepted 0, Dropped 0
2026-03-25T21:28:17Noticesuricata[109384] <Notice> -- (W-8000) Treated: Pkts 0, Bytes 0, Errors 0
2026-03-25T21:28:17Noticesuricata[109383] <Notice> -- (W-8000) Verdict: Accepted 0, Dropped 0
2026-03-25T21:28:17Noticesuricata[109383] <Notice> -- (W-8000) Treated: Pkts 0, Bytes 0, Errors 0
2026-03-25T21:28:17Noticesuricata[109382] <Notice> -- (W-8000) Verdict: Accepted 0, Dropped 0
2026-03-25T21:28:17Noticesuricata[109382] <Notice> -- (W-8000) Treated: Pkts 0, Bytes 0, Errors 0
2026-03-25T21:28:17Noticesuricata[109381] <Notice> -- (W-8000) Verdict: Accepted 0, Dropped 0
2026-03-25T21:28:17Noticesuricata[109381] <Notice> -- (W-8000) Treated: Pkts 723, Bytes 35427, Errors 0
2026-03-25T21:28:17Noticesuricata[109380] <Notice> -- (W-8000) Verdict: Accepted 0, Dropped 0
2026-03-25T21:28:17Noticesuricata[109380] <Notice> -- (W-8000) Treated: Pkts 724, Bytes 35476, Errors 0
2026-03-25T21:28:17Noticesuricata[109379] <Notice> -- (W-8000) Verdict: Accepted 0, Dropped 0
2026-03-25T21:28:17Noticesuricata[109379] <Notice> -- (W-8000) Treated: Pkts 724, Bytes 35476, Errors 0
#2
26.1 Series / Re: Suricata - Divert (IPS)
March 25, 2026, 08:46:08 PM
I an new to opnsense and have set up an transparent firewall bridge between ISP and my unifi router. Does this setup work with a transparent bridge too? I have made the fw rule on wan interface with divert to, but i can't see any IPS dropping in logs.