Suricata, Tagged Packets and Interfaces
I hope this is a simple question but im wondering how Suricata handles vlans on interfaces…
I have my LAN interface with most traffic untagged and on top of that i have a tagged logically separate interface called Wireless for vlan 30 using the same NIC.
In Suricata i had configured both LAN and Wireless interfaces but it seems all Wireless traffic is still seen via LAN which kind of makes sense.
I assume I don't need a separate ruleset for Wireless as it uses the same physical NIC, would that be correct?