IPS PPPoE Interface

Started by juliocbc, September 20, 2018, 08:33:17 PM

Previous topic - Next topic
December 13, 2024, 02:56:03 PM #15 Last Edit: December 13, 2024, 03:08:35 PM by yeraycito
Suricata can function as an IPS with PPPoE without any problems, you just need to make a few modifications:

- Configure the WAN interface as none (IPv4 Configuration Type none)

- Add a new OPT interface with the PPPoE configuration just like it was a WAN PPPoE.

- Configure Suricata as IPS on WAN.

Quote from: yeraycito on December 13, 2024, 02:56:03 PMSuricata can function as an IPS with PPPoE without any problems, you just need to make a few modifications:

- Configure the WAN interface as none (IPv4 Configuration Type none)

- Add a new OPT interface with the PPPoE configuration just like it was a WAN PPPoE.

- Configure Suricata as IPS on WAN.

Interesting topic.

Wow, I have read everywhere that with PPPoE it was not possible, I just tried and it runs. Thank you for this tip
Deciso DEC850v2

Can highlight this issue to dev @ FreeBSD?

Can highlight this issue to dev @ FreeBSD?

Yes, you can. Use the freebsd-net mailing list or the FreeBSD bug tracker.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Quote from: yeraycito on December 13, 2024, 02:56:03 PMSuricata can function as an IPS with PPPoE without any problems, you just need to make a few modifications:

- Configure the WAN interface as none (IPv4 Configuration Type none)

- Add a new OPT interface with the PPPoE configuration just like it was a WAN PPPoE.

- Configure Suricata as IPS on WAN.

There's another action you should take with this scenario:
You have to manually add your public IP address to IDS (advanced mode) --> "Home Networks"

Almost in my case, there's a huge difference in triggered alerts, just try with and without it, and take a look in Alerts.