Xentrk
Part of the Furniture
Hope you get feeling better @M@rco.
I had Suricata installed on my pfSense box for a brief time. I had issues with tuning it over all of the interfaces I run. I recently changed to Snort as they have an updated method to configure. Rather than having individual rules, they have several categories you can choose from. What I like about pfSense is you have GUI menus for Suricata and Snort which makes things much easier.
Here are some videos on Suricata and Snort on pfSense. Still good to watch even though you are using different firmware. This video is one of the better ones I have seen on Suricata. This video discusses the Snort features I mentioned above. Right now, I only have Snort enabled on my WAN interface as I was having issues with streaming over the VPN tunnel. I have not had time to work on it recently.
I had Suricata installed on my pfSense box for a brief time. I had issues with tuning it over all of the interfaces I run. I recently changed to Snort as they have an updated method to configure. Rather than having individual rules, they have several categories you can choose from. What I like about pfSense is you have GUI menus for Suricata and Snort which makes things much easier.
Here are some videos on Suricata and Snort on pfSense. Still good to watch even though you are using different firmware. This video is one of the better ones I have seen on Suricata. This video discusses the Snort features I mentioned above. Right now, I only have Snort enabled on my WAN interface as I was having issues with streaming over the VPN tunnel. I have not had time to work on it recently.