Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG-4860 Suricata Inline IPS

    Scheduled Pinned Locked Moved IDS/IPS
    2 Posts 2 Posters 290 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      petrt3522
      last edited by petrt3522

      I was curious if anyone can confirm if the 4860 can do Suricata In-line IPS. I just enabled to Inline and no alerts seem to be populating.

      Additionally, the reason I enabled is that I was seeing traffic leakage from a dual OpenVPN tunnel, where I had Suricata legacy enabled led on each tunnel; however on daily occasions would see Blocks/alerts being caught by the WAN-Suricata (also Legacy). I am at a loss of why this was occurring, as the OpenVPN IPS’ were supposed to allow the traffic though the tunnels anyway; but that traffic was not to go out the unencrypted default WAN, Rules were in place to block anything from the Source Interface going to the WAN (firewall policy route to an Interface Gateway Group of the OpenVPN interfaces).

      Packet captures run through SSH of the 4860 WAN interface showed the same traffic leakage shown in the Suricata ‘Block’ logs.

      Are there any thoughts on these 2 items?

      Thank you

      NollipfSenseN 1 Reply Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense @petrt3522
        last edited by

        @petrt3522 Any Netgate hardware would, I believe because they would use a NIC that supports!

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.