Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Zenarmor (Sensei)
»
Zenarmor will not run WAN along side of Suracata
« previous
next »
Print
Pages: [
1
]
Author
Topic: Zenarmor will not run WAN along side of Suracata (Read 523 times)
battle
Newbie
Posts: 18
Karma: 0
Zenarmor will not run WAN along side of Suracata
«
on:
September 30, 2024, 04:05:33 pm »
If I try to check both WAN and LAN boxes in settings, Zenarmor says that I can't run WAN on both Suracata and Zenarmor (see quote below). So if I uncheck 'Enable' and 'IPS mode' and all other boxes on the Suracata 'Services: Intrusion Detection: Administration' page, Zenarmor will still not allow me to check the WAN box in Zenarmor/Settings. There doesn't seem to be a way to only run Zenarmor.
"When you use IPS & Zenarmor together, you can only use the WAN interface for Suricata
It looks like you also have Suricata configured to run on this interface. Please be noted that Zenarmor and Suricata cannot be run on the same ethernet interface at the same time."
Logged
IHK
Jr. Member
Posts: 99
Karma: 5
Re: Zenarmor will not run WAN along side of Suracata
«
Reply #1 on:
September 30, 2024, 06:07:42 pm »
Wan interfaces (OpnSense) are also filtered and interfaces are used as the default gateway because the wan interfaces of opnsense are also filtered by suricata. Zenarmor and suricata use netmap and both do not work on the same interface! To prevent a network issue, Zenarmor does not allow you to protect these interfaces.
If you protect all LAN interfaces on Zenarmor, it has no benefit to protect WAN as well. Zenarmor already inspect all outbound traffic via LAN interface(s)
Logged
battle
Newbie
Posts: 18
Karma: 0
Re: Zenarmor will not run WAN along side of Suracata
«
Reply #2 on:
October 01, 2024, 03:15:05 am »
Thanks. I received like info from someone else. Zenarmor is watching LAN and Surcata is watching WAN now.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Zenarmor (Sensei)
»
Zenarmor will not run WAN along side of Suracata