Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata on Trunk Interface & it's VLAN Subinterfaces

    Scheduled Pinned Locked Moved IDS/IPS
    3 Posts 2 Posters 674 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      follysuperscript
      last edited by

      Hello,

      I'm seeing traffic from VLAN sub-interfaces showing up in the trunk interface. Is this expected behavior? It appears this traffic is sometimes showing up in both interfaces and sometimes only one (the Trunk, even when it's VLAN traffic).

      I have a single WAN port and a LAN port that caries native (management) VLAN traffic and also tagged VLAN traffic. I have Suricata setup for ever interface, physical and VLAN.

      WAN
      LAN (Native 1)

      • VLAN192
      • VLAN172

      Example: I'll see traffic for VLAN192 interface in Suricata on LAN, but not in VLAN192.
      Another Exmaple: I'll see traffic from VLAN172 on Suricata in LAN and VLAN172

      Any help appreciated! Thanks for this great software :)

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by bmeeks

        Suricata puts the interface it runs on in promiscuous mode in order to see all traffic, so this would include all VLANs on a trunk. So with Suricata running on your LAN, it will see all the traffic passing through the physical LAN interface. There is an option on the INTERFACE SETTINGS tab for each interface where you can disable promiscuous mode. You can try toggling that and restarting Suricata on the interface to see if that helps separate logged traffic any better.

        1 Reply Last reply Reply Quote 0
        • F
          follysuperscript
          last edited by

          Thank you for the help. I'll try that out.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.