LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-13-2018, 09:55 PM   #1
JJJCR
Senior Member
 
Registered: Apr 2010
Posts: 2,158

Rep: Reputation: 449Reputation: 449Reputation: 449Reputation: 449Reputation: 449
Cool Suricata as IPS


Hi guys, anyone tried using suricata for IPS?

In a local LAN and with unmanaged switches, Suricata can just be installed on any PCs and it's able to detect the activity for the whole network?

or it has to be located on an a location were all traffic will pass through?

Thanks.
 
Old 11-16-2018, 05:59 PM   #2
RickDeckard
Member
 
Registered: Jan 2014
Location: Canton, Georgia, USA
Distribution: Debian 12
Posts: 205

Rep: Reputation: Disabled
An IDPS like Suricata should always be installed inline for best results. Do you want it to detect attacks as they are happening? Or do you want it to detect copied attack traffic?
 
1 members found this post helpful.
Old 11-18-2018, 07:33 PM   #3
JJJCR
Senior Member
 
Registered: Apr 2010
Posts: 2,158

Original Poster
Rep: Reputation: 449Reputation: 449Reputation: 449Reputation: 449Reputation: 449
- Copied attack traffic

For detect attacks as they are happening, I have to connect it like some sort a proxy connection? In which all the traffic will pass through Suricata.
 
Old 11-19-2018, 07:55 AM   #4
//////
Member
 
Registered: Nov 2005
Location: Land of Linux :: Finland
Distribution: Arch Linux && OpenBSD 7.4 && Pop!_OS && Kali && Qubes-Os
Posts: 824

Rep: Reputation: 350Reputation: 350Reputation: 350Reputation: 350
Quote:
Originally Posted by JJJCR View Post
- Copied attack traffic

For detect attacks as they are happening, I have to connect it like some sort a proxy connection? In which all the traffic will pass through Suricata.
use network bridge.
thats what i am using.

|internet|-----------------|bridge(openbsd or linux)|------------|private network|

one thing that you could use is pfsense firewall, when i used it it had snort and suricata available for users.
 
1 members found this post helpful.
Old 11-21-2018, 07:16 PM   #5
JJJCR
Senior Member
 
Registered: Apr 2010
Posts: 2,158

Original Poster
Rep: Reputation: 449Reputation: 449Reputation: 449Reputation: 449Reputation: 449
Thanks buddy! Cheers!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Allow internal ips block external ips Jz87 Linux - Security 10 07-19-2010 09:42 PM
cURL: Server has many IPs, how would I make a cURL script use those IPs to send data? guest Programming 0 04-11-2009 11:42 AM
Getting things straight: Apache, SSL, Multiple External IPs / Internal IPs robin.com.au Linux - Server 21 10-13-2007 11:39 PM
how to define a specific range of IPs and/or multiple IPs in an iptables rule?... TheHellsMaster Linux - Security 9 09-20-2004 10:06 AM
eth0:9 incorrect IPs ,and eth0 not IPs WannaLearnLinux Linux - Networking 10 10-26-2003 08:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:47 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration