Suricata, Tagged Packets and Interfaces

  • Hi All,
      I hope this is a simple question but im wondering how Suricata handles vlans on interfaces…

    I have my LAN interface with most traffic untagged and on top of that i have a tagged logically separate interface called Wireless for vlan 30 using the same NIC.

    In Suricata i had configured both LAN and Wireless interfaces but it seems all Wireless traffic is still seen via LAN which kind of makes sense.

    I assume I don't need a separate ruleset for Wireless as it uses the same physical NIC, would that be correct?

