Surricata blocks traffic on local allowed list

Started by steilfirn_8000, February 05, 2023, 10:28:03 AM

Previous topic - Next topic
Not sure if this is relevant for this topic but with my new router setup I am also using Suricata as IDS/IPS (from SELKS https://github.com/StamusNetworks/SELKS) with equal settings as on OPNsense.

With this setup it is not having any troubles with my LAN & remote sites.

QuoteNot sure if this is relevant for this topic
it's hard to say, since so far only false positive alerts (fixable) and possible misconfig are visible imho


for the ref. false-drop records fixed in https://github.com/OISF/suricata/commit/517132b6ad0347c8402b3aace885d1b734609fec
although I still think it would be great to be able to disable drop-log on the OPN