Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can an IDS/IPS be implemented on the 2100 model ?

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      LeMike
      last edited by

      Is it possible to implement the same IDS/IPS on this 2100 model than the one included in the 5100 model ?
      If so, how can this be done ?
      I cannot afford a bigger Netgate model than 2100 model, but I'm very conscient of IT Security.

      Thanks
      Mike

      stephenw10S 1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator @LeMike
        last edited by

        Yes you can run Snort or Suricata on the 2100.
        The only restriction there is that you cannot usefully use in-line mode because the mvneta NICs are not supported by netmap directly.

        Steve

        L 1 Reply Last reply Reply Quote 1
        • L
          LeMike @stephenw10
          last edited by LeMike

          Thanks @stephenw10, and is that very bad ? How much different is this against upper models ?
          I mean, would my PCs be more vulnerable than using an upper model ?

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @LeMike
            last edited by

            @lemike What speed is your connection? High speeds will cause more CPU usage on the 2100.

            We do have Snort or Suricata running on multiple 2100s at clients so yes it does work. It's probably a bit more useful for open ports like a web server, since a web browser is most likely using HTTPS and the IDS can't see the encrypted traffic.

            Inline mode works if the NIC supports it. There is some extra/manual setup. The idea is the packets can get blocked individually in real time, vs. Legacy mode adds a block in the firewall on the IP, that lasts for "n" minutes, but can take a few microseconds to add. I have tried inline, a while back (not on a 2100), had strange problems, and so we only use the default Legacy mode. See Bill's posts in the IDS forum/category for how Inline works.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote ๐Ÿ‘ helpful posts!

            L 1 Reply Last reply Reply Quote 0
            • L
              LeMike @SteveITS
              last edited by

              @steveits Hello Steve, I have 40Mbps for download, 3 Mbps for upload.
              When you say: Inline mode works if the NIC supports it - Do you mean the NIC on the Netgate appliance ? or local PCs ?

              Thanks.

              S 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @LeMike
                last edited by

                @lemike 40 Mbit should be fine on the 2100.

                re: NIC, the NIC on the 2100 where Snort or Suricata is running.

                https://forum.netgate.com/topic/143812/snort-package-4-0-inline-ips-mode-introduction-and-configuration-instructions and other pinned posts in the IDS category.

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote ๐Ÿ‘ helpful posts!

                L 1 Reply Last reply Reply Quote 1
                • L
                  LeMike @SteveITS
                  last edited by

                  @steveits Great information Steve! I willl take a deep look at it.

                  Best Regards, and Thank you!
                  LeMike

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.