Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - lylybr

#1
Hi everyone,

I recently changed the interface layout on my OPNsense firewall and noticed something I did not expect with Suricata IDS.

Before the change, Suricata was monitoring my LAN interface and the alerts were easy to associate with traffic from my internal clients. After moving the IDS configuration to another interface, I still see Suricata running and processing traffic, but the number of alerts has dropped significantly.

For example, normal DNS and HTTP/HTTPS traffic is visible in the firewall logs, but some traffic that previously generated Suricata alerts no longer appears in the IDS event list.

My setup is roughly:

OPNsense 26.x
Suricata enabled in IDS mode
ET Open rules enabled
LAN and an additional interface are being monitored
No custom Suricata rules
Hardware offloading is disabled

Is there a specific interface or Home Networks configuration I should check when moving Suricata monitoring between interfaces?

I'm especially interested in understanding whether the interface selection changes which traffic Suricata can actually inspect, rather than simply affecting what is displayed in the alerts.

If anyone has a similar setup, I'd appreciate hearing how you configured the monitored interfaces and Home Networks.