I have been running Opnsense on a HP t730 Thin Client for over a year using 2 of the 4 ports on the BCM95719A1904G NIC for WAN and LAN.
Throughout all that time I have never got Suricata to detect anything either on LAN or WAN. Even with the EICAR test rule.
I used to use ZENArmor but found that would stop network flow randomly after a couple of days so uninstalled it.
I think the NIC is running as generic emulated or something similar.
My question is has anyone any issues with this card or can offer any advice why Suricata fails to detect any malware, even when using the EICAR txt test ?
Or is it the case that the emulated nic driver is not compatible with Suricata/Zenarmour etc ?