Suricata and OpenVPN
-
I run an OpenVPN client on pfsense to connect to a VPN service provider (i.e. NordVPN) and would like to understand how to configure suricata for this setup.
I figured inline mode on the OpenVPN interface should be sufficient.
Should I also enable on the WAN interface since all my traffic should be routing through the OpenVPN interface ?
-
after reading a few posts ... I think the answer is to setup suricata on the lan interface rather than the wan or openvpn interfaces ?
-
@johnha said in Suricata and OpenVPN:
after reading a few posts ... I think the answer is to setup suricata on the lan interface rather than the wan or openvpn interfaces ?
For the vast majority of home network situations, when you want to run an IDS. the LAN is the best place to put it.