1
16.1 Legacy Series / Suricata and PF Interaction Clarification
« on: January 31, 2016, 04:39:58 am »
The current "IDS" package in OPNsense, (Suricata IDS) is fresh enough that I don't understand where the packets get filtered.
I'm curious about the interaction between the Suricata IDS, and PF, when using the package in "IPS" mode?
The idea of filtering packets based on various packet content matches is obviously quite a powerful tool, and I'd love to know where the edges are here in OPNsense!
I'm curious about the interaction between the Suricata IDS, and PF, when using the package in "IPS" mode?
- Does PF filter the packet first, or does the IPS?
- Can the Suricata rules be picked up by PF rules, (particularly rules which redirect the packet in some way- not block or deny?)
- Is Suricata really best to stand alone, (perhaps as an inline transparent bridge?)
The idea of filtering packets based on various packet content matches is obviously quite a powerful tool, and I'd love to know where the edges are here in OPNsense!