pfsense + Suricata + Security Onion #7577
-
Hi, I was using Suricata in Security Onion to get IDS alerts and since SO does not support Suricata IPS I started exploring pfSense Suricata IDS/IPS. Now I've Suricata IDS alerts in SO as well as in pfSense. In addition to this Suricata in pfSense can do the blocking part using legacy-mode blocking. It means IPS is sorted in pfSense. If I want to integrate Security onion and pfSense for Suricata IDS/IPS then what would be the best possible solution:
Kindly share suggestions. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
This is answered in forums |
Beta Was this translation helpful? Give feedback.
This is answered in forums
https://forum.netgate.com/topic/170831/suricata-ips/5
https://forum.suricata.io/t/pfsense-suricata-security-onion/2321