Making an inline Suricata box using OPNsense

Started by liver007, August 07, 2019, 10:47:32 AM

Previous topic - Next topic
August 07, 2019, 10:47:32 AM Last Edit: August 29, 2019, 06:56:59 AM by fabian
HI
I'm looking to make an inline Suricata box to intercept certain applications. I need DPI to detect certain applications (i.e. unauthorized VPN traffic) and block it. The box needs to be inline and receive its LAN IP address from the DCHP server.

I have been looking at OPNsense (as opposed to Security Onion) to do this project quickly but got lost in the configurations. Is there a knowledgebase article to setup OPNsense in bridge mode to transparently pass through traffic with Suricata IPS active?