<div dir="ltr">Hi Victor Julien,<div><br></div><div>I am able to run suricata in af-packet tap mode, between two physical interfaces say eth0 and eth1 where there is no linux bridge involved (basic inline mode).</div><div><br></div><div><span style="color:rgb(80,0,80)"> suricata.yaml:</span><br style="color:rgb(80,0,80)"><span style="color:rgb(80,0,80)">  - interface: eth0</span></div><div><span style="color:rgb(80,0,80)">     threads: 1</span><br style="color:rgb(80,0,80)"><span style="color:rgb(80,0,80)">     defrag: ye</span><br style="color:rgb(80,0,80)"><span style="color:rgb(80,0,80)">     cluster-id: 98</span><br style="color:rgb(80,0,80)"><span style="color:rgb(80,0,80)">     copy-mode: ips</span><br style="color:rgb(80,0,80)"><span style="color:rgb(80,0,80)">     copy-iface: eth1</span><br style="color:rgb(80,0,80)"><span style="color:rgb(80,0,80)">     use-mmap: yes</span><br></div><div><br></div><div>Regards</div><div>-Kavi Perumal G.</div></div><br><div class="gmail_quote"><div dir="ltr">On Thu, Nov 8, 2018 at 4:37 PM Victor Julien <<a href="mailto:lists@inliniac.net">lists@inliniac.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 08-11-18 10:35, kavi perumal wrote:<br>
> A very basic clarification w.r.t suricata IDS/IPS af-packet mode.<br>
> i want to run suricata in IPS --af-packet mode, but would like to use a<br>
> physical interface (eth0) and a bridge(br0) as a pair, where as eth0 is<br>
> not part of the bridge (br0).<br>
> <br>
> suricata.yaml:<br>
>  - interface: eth0<br>
>     threads: 1<br>
>     defrag: yes<br>
>     cluster-id: 98<br>
>     copy-mode: ips<br>
>     copy-iface: br0<br>
>     use-mmap: yes<br>
> <br>
<br>
I wonder if the problem is that you're creating a Suricata bridge that<br>
includes a kernel level bridge. Are you able to get it working w/o using<br>
a br0 but instead a real interface?<br>
<br>
-- <br>
---------------------------------------------<br>
Victor Julien<br>
<a href="http://www.inliniac.net/" rel="noreferrer" target="_blank">http://www.inliniac.net/</a><br>
PGP: <a href="http://www.inliniac.net/victorjulien.asc" rel="noreferrer" target="_blank">http://www.inliniac.net/victorjulien.asc</a><br>
---------------------------------------------<br>
<br>
_______________________________________________<br>
Suricata IDS Users mailing list: <a href="mailto:oisf-users@openinfosecfoundation.org" target="_blank">oisf-users@openinfosecfoundation.org</a><br>
Site: <a href="http://suricata-ids.org" rel="noreferrer" target="_blank">http://suricata-ids.org</a> | Support: <a href="http://suricata-ids.org/support/" rel="noreferrer" target="_blank">http://suricata-ids.org/support/</a><br>
List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users" rel="noreferrer" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users</a><br>
<br>
Conference: <a href="https://suricon.net" rel="noreferrer" target="_blank">https://suricon.net</a><br>
Trainings: <a href="https://suricata-ids.org/training/" rel="noreferrer" target="_blank">https://suricata-ids.org/training/</a></blockquote></div>