Pfsense: is it possible transparent suricata and router on the same box?

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

markchang

New Member
May 13, 2020
1
0
1
Inspired by cheep quad port 2.5G routers growing in performance and dropping in price, i acquired one. However, in my usage, since my lab got some public IP to work on, i setup pfsense to act as a transparent bridge running suricata for IDS. However, in order t connect my Pfsense box to network for downloading new suricata definitions, it seems to go to a broadcast storm situation. Is this a good idea? or i should consider other methods? ( the link causing problems are the red connection in attachments )
 

Attachments

louie1961

Active Member
May 15, 2023
336
146
43
I think the better answer would be to install Proxmox on your quad port router, pass through two nics to pfSense and two to the VM running suricata. Then treat them as separate physical devices.