default setup and
Suricata - IDS/IPS on AsusWRT Merlin setup same log.
18/5/2020 -- 20:26:05 - <Notice> - This is Suricata version 4.1.7 RELEASE
18/5/2020 -- 20:26:05 - <Info> - CPUs/cores online: 2
18/5/2020 -- 20:26:05 - <Info> - Found an MTU of 1500 for 'eth0'
18/5/2020 -- 20:26:05 - <Info> - Found an MTU of 1500 for 'eth0'
18/5/2020 -- 20:26:05 - <Info> - fast output device (regular) initialized: fast.log
18/5/2020 -- 20:26:05 - <Info> - Unified2-alert initialized: filename unified2.alert, limit 32 MB
18/5/2020 -- 20:26:05 - <Info> - http-log output device (regular) initialized: http.log
18/5/2020 -- 20:26:05 - <Info> - stats output device (regular) initialized: stats.log
18/5/2020 -- 20:26:05 - <Info> - Syslog output initialized
18/5/2020 -- 20:26:05 - <Info> - eve-log output device (regular) initialized: eve-%Y-%m-%d-%H:%M.json
18/5/2020 -- 20:26:05 - <Info> - 12 rule files processed. 2676 rules successfully loaded, 0 rules failed
18/5/2020 -- 20:26:05 - <Info> - Threshold config parsed: 0 rule(s) found
18/5/2020 -- 20:26:05 - <Info> - 2676 signatures processed. 113 are IP-only rules, 297 are inspecting packet payload, 2378 inspect application layer, 0 are decoder event only
18/5/2020 -- 20:26:06 - <Notice> - AFL mode starting
18/5/2020 -- 20:26:06 - <Notice> - AFL mode starting
18/5/2020 -- 20:26:06 - <Notice> - all 2 packet processing threads, 0 management threads initialized, engine started.
18/5/2020 -- 20:26:07 - <Info> - All AFP capture threads are running.
_____________________________________________________________________
with this setting, the vpn data transfer power is slightly reduced because the suricata is visibly working. I can't test yet if the IPS actually works, but it writes that in the log.
# Runmode the engine should use.
runmode: workers
# Specifies the kind of flow load balancer used by the flow pinned autofp mode.
autofp-scheduler: active-packets
# If set to auto, the variable is internally switched to 'router' in IPS
# mode and 'sniffer-only' in IDS mode.
host-mode: router
# Linux high speed capture support
af-packet:
- interface: eth0
threads: auto
defrag: yes
cluster-type: cluster_flow
cluster-id: 98
copy-mode: ips
copy-iface: br0
buffer-size: 64535
use-mmap: yes
- interface: br0
threads: auto
cluster-id: 97
defrag: yes
cluster-type: cluster_flow
copy-mode: ips
copy-iface: eth0
buffer-size: 64535
use-mmap: yes
18/5/2020 -- 20:44:53 - <Notice> - This is Suricata version 4.1.7 RELEASE
18/5/2020 -- 20:44:53 - <Info> - CPUs/cores online: 2
18/5/2020 -- 20:44:53 - <Info> - Found an MTU of 1500 for 'eth0'
18/5/2020 -- 20:44:53 - <Info> - Found an MTU of 1500 for 'eth0'
18/5/2020 -- 20:44:53 - <Info> - Found an MTU of 1500 for 'br0'
18/5/2020 -- 20:44:53 - <Info> - Found an MTU of 1500 for 'br0'
18/5/2020 -- 20:44:53 - <Notice> - using flow hash instead of active packets
18/5/2020 -- 20:44:53 - <Info> - AF_PACKET: Setting IPS mode
18/5/2020 -- 20:44:53 - <Info> - fast output device (regular) initialized: fast.log
18/5/2020 -- 20:44:53 - <Info> - Unified2-alert initialized: filename unified2.alert, limit 32 MB
18/5/2020 -- 20:44:53 - <Info> - http-log output device (regular) initialized: http.log
18/5/2020 -- 20:44:53 - <Info> - stats output device (regular) initialized: stats.log
18/5/2020 -- 20:44:53 - <Info> - Syslog output initialized
18/5/2020 -- 20:44:53 - <Info> - eve-log output device (regular) initialized: eve-%Y-%m-%d-%H:%M.json
18/5/2020 -- 20:44:53 - <Info> - 12 rule files processed. 2676 rules successfully loaded, 0 rules failed
18/5/2020 -- 20:44:53 - <Info> - Threshold config parsed: 0 rule(s) found
18/5/2020 -- 20:44:53 - <Info> - 2676 signatures processed. 113 are IP-only rules, 297 are inspecting packet payload, 2378 inspect application layer, 0 are decoder event only
18/5/2020 -- 20:44:54 - <Info> - AF_PACKET IPS mode activated eth0->br0
18/5/2020 -- 20:44:54 - <Info> - Going to use 2 thread(s)
18/5/2020 -- 20:44:54 - <Notice> - AFL mode starting
18/5/2020 -- 20:44:54 - <Notice> - AFL mode starting
18/5/2020 -- 20:44:54 - <Info> - AF_PACKET IPS mode activated br0->eth0
18/5/2020 -- 20:44:55 - <Info> - Going to use 2 thread(s)
18/5/2020 -- 20:44:55 - <Notice> - AFL mode starting
18/5/2020 -- 20:44:55 - <Info> - Found an MTU of 1500 for 'br0'
18/5/2020 -- 20:44:55 - <Info> - Found an MTU of 1500 for 'eth0'
18/5/2020 -- 20:44:55 - <Notice> - AFL mode starting
18/5/2020 -- 20:44:55 - <Info> - Found an MTU of 1500 for 'br0'
18/5/2020 -- 20:44:55 - <Info> - Found an MTU of 1500 for 'eth0'
18/5/2020 -- 20:44:55 - <Notice> - all 4 packet processing threads, 0 management threads initialized, engine started.
18/5/2020 -- 20:44:55 - <Info> - All AFP capture threads are running.