Suricata synchronize settings on all interfaces...?
-
Is there a way to synchronize rulesettings across interfaces?
-
Across interfaces on the same box, "no". Across interfaces on different firewalls, "yes" (provided the two firewalls have identical NIC hardware and the same interface layout).
You can clone an existing interface when creating a new one. That makes the new interface identical to its parent. But this is a one-time event. They do not then auto-sync with each other going forward.
You could accomplish synchronzing rules using the SID MGMT tab feature. Simply assign the same SID conf files to each interface.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.