Hi @zemsten, I'm not quite sure if I understand completely. Do you still have the problem with Suricata in IPS mode?
hw.ixl.enable_head_writeback="0"net.enc.in.ipsec_bpf_mask="2"net.enc.in.ipsec_filter_mask="2"net.enc.out.ipsec_bpf_mask="1"net.enc.out.ipsec_filter_mask="1"net.inet.icmp.reply_from_interface="1"net.local.dgram.maxdgram="8192"vfs.read_max="128"net.inet.ip.portrange.first="1024"net.inet.tcp.blackhole="2"net.inet.udp.blackhole="1"net.inet.ip.random_id="1"net.inet.ip.sourceroute="0"net.inet.ip.accept_sourceroute="0"net.inet.icmp.log_redirect="0"net.inet.tcp.drop_synfin="1"net.inet6.ip6.redirect="1"net.inet6.ip6.use_tempaddr="0"net.inet6.ip6.prefer_tempaddr="0"net.inet.tcp.syncookies="1"net.inet.tcp.recvspace="65536"net.inet.tcp.sendspace="65536"net.inet.tcp.delayed_ack="0"net.inet.udp.maxdgram="57344"net.link.bridge.pfil_onlyip="0"net.link.bridge.pfil_local_phys="0"net.link.bridge.pfil_member="1"net.link.bridge.pfil_bridge="0"net.link.tap.user_open="1"kern.randompid="347"net.inet.ip.intr_queue_maxlen="1000"hw.syscons.kbd_reboot="0"net.inet.tcp.log_debug="0"net.inet.icmp.icmplim="0"net.inet.tcp.tso="0"net.inet.udp.checksum="1"kern.ipc.maxsockbuf="4262144"vm.pmap.pti="0"hw.ibrs_disable="0"security.bsd.see_other_gids="0"security.bsd.see_other_uids="0"net.inet.ip.redirect="0"net.inet.icmp.drop_redirect="1"net.inet.tcp.hostcache.cachelimit="0"net.inet.tcp.soreceive_stream="1"net.isr.maxthreads="-1"net.isr.bindthreads="1"net.pf.source_nodes_hashsize="1048576"cc_cubic_load="YES"net.inet.tcp.cc.algorithm="cubic"net.link.ifqmaxlen="512"net.inet.tcp.recvbuf_inc="65536"net.inet.tcp.recvbuf_max="4194304"net.inet.tcp.sendbuf_inc="65536"net.inet.tcp.sendbuf_max="4194304"net.inet.tcp.mssdflt="1460"net.inet.tcp.minmss="536"net.inet.tcp.abc_l_var="44"net.inet.tcp.initcwnd_segments="44"net.inet.tcp.rfc6675_pipe="1"dev.em.0.fc="0"dev.em.1.fc="0"dev.em.2.fc="0"dev.em.3.fc="0"net.bpf.zerocopy_enable="1"