Hi @Monviech,
I have a follow-up question regarding Divert mode.
My setup is:
- One WAN and one LAN
- Zenarmor is enabled on the LAN interface
- Suricata is running in Divert (IPS) mode
- On LAN I added a Pass + divert-to Intrusion Detection rule (Source: LAN net, Destination: any) above the default "Allow LAN to any" rule.
Everything works as expected:
- Zenarmor inspects the traffic.
- Suricata generates alerts and blocks traffic when configured.
- Traffic matching the divert rule never reaches the default "Allow LAN to any" rule, which I understand is expected.
Is this considered a valid and recommended configuration for a simple home network?
Or would you recommend a different placement of the "divert-to" rule?
Also, is running Zenarmor on LAN together with a "divert-to" rule on the same interface a supported configuration?
Thank you!
I have a follow-up question regarding Divert mode.
My setup is:
- One WAN and one LAN
- Zenarmor is enabled on the LAN interface
- Suricata is running in Divert (IPS) mode
- On LAN I added a Pass + divert-to Intrusion Detection rule (Source: LAN net, Destination: any) above the default "Allow LAN to any" rule.
Everything works as expected:
- Zenarmor inspects the traffic.
- Suricata generates alerts and blocks traffic when configured.
- Traffic matching the divert rule never reaches the default "Allow LAN to any" rule, which I understand is expected.
Is this considered a valid and recommended configuration for a simple home network?
Or would you recommend a different placement of the "divert-to" rule?
Also, is running Zenarmor on LAN together with a "divert-to" rule on the same interface a supported configuration?
Thank you!
"