[Oisf-users] Reg: [oisf-users] Can i use a bridge and ethernet interface as two different interfaces in af-packet IPS?

kavi perumal kaviperumal22 at gmail.com
Thu Nov 8 09:35:05 UTC 2018


Hi,

A very basic clarification w.r.t suricata IDS/IPS af-packet mode.
i want to run suricata in IPS --af-packet mode, but would like to use a
physical interface (eth0) and a bridge(br0) as a pair, where as eth0 is not
part of the bridge (br0).

suricata.yaml:
 - interface: eth0
    threads: 1
    defrag: yes
    cluster-id: 98
    copy-mode: ips
    copy-iface: br0
    use-mmap: yes

Regards
-Kavi Perumal G.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20181108/89dd30df/attachment.html>


More information about the Oisf-users mailing list