Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Gorpes

#1
Hi @Monviech,

I have a follow-up question regarding Divert mode.

My setup is:

- One WAN and one LAN
- Zenarmor is enabled on the LAN interface
- Suricata is running in Divert (IPS) mode
- On LAN I added a Pass + divert-to Intrusion Detection rule (Source: LAN net, Destination: any) above the default "Allow LAN to any" rule.

Everything works as expected:

- Zenarmor inspects the traffic.
- Suricata generates alerts and blocks traffic when configured.
- Traffic matching the divert rule never reaches the default "Allow LAN to any" rule, which I understand is expected.

Is this considered a valid and recommended configuration for a simple home network?

Or would you recommend a different placement of the "divert-to" rule?

Also, is running Zenarmor on LAN together with a "divert-to" rule on the same interface a supported configuration?

Thank you!