[Oisf-users] Does suricata support Different rulesets for each interface

Özkan KIRIK ozkan.kirik at gmail.com
Thu Apr 13 15:40:01 UTC 2017


Thank you Andreas

On Tue, Apr 11, 2017 at 11:46 PM, Andreas Herz <andi at geekosphere.org> wrote:

> On 11/04/17 at 22:23, Özkan KIRIK wrote:
> > I need to perform different rulesets for each interface.
> > For example for WAN interface the ruleset will contain espcialls DoS and
> > SQL injection rules. For LAN interface the ruleset will contain P2P
> rules.
>
> One "simple" approach would be to use two dedicated config files and you
> pass one for one suricata instance with -c /PATH/wan.yaml and another
> one with the second instance with -c /PATH/lan.yaml.
>
>
> --
> Andreas Herz
> _______________________________________________
> Suricata IDS Users mailing list: oisf-users at openinfosecfoundation.org
> Site: http://suricata-ids.org | Support: http://suricata-ids.org/support/
> List: https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20170413/48b8f052/attachment-0002.html>


More information about the Oisf-users mailing list