pfsense:suricata
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
pfsense:suricata [2021/01/15 01:20] – peter | pfsense:suricata [2021/07/20 11:39] (current) – peter | ||
---|---|---|---|
Line 1: | Line 1: | ||
====== PFSense - Suricata ====== | ====== PFSense - Suricata ====== | ||
- | Suricata | + | See [[IDS:Suricata|Suricata]] |
- | * Network Intrusion Detection | + | ---- |
- | * Network Intrusion Prevention | + | |
- | * Network Security Monitoring | + | |
- | ==== IDS (Intrusion Detection System) ==== | ||
- | * Passive | + | ===== Suricata in pfSense ===== |
- | * Out of line | + | |
- | * On tap or span port | + | |
- | ==== IPS (Intrusion Prevention System) ==== | + | The GUI code for Suricata is all written in PHP. All that PHP code does is provide a fancy user interface for choosing parameters which populate the suricata.yaml configuration file that the Suricata binary needs to run. All of the " |
- | * Active | + | All of the PHP code lives in / |
- | * Inline | + | |
- | * Router or bridge | + | |
- | + | ||
- | ==== NSM (Network Security Monitoring) ==== | + | |
- | + | ||
- | * Not ‘just’ generating alerts, but also informational events like HTTP requests, TLS transfers, etc | + | |
- | * Full Packet Capture (FPC) for being able to dig deep into traffic if necessary | + | |
- | * Produces LOTS of data | + | |
---- | ---- | ||
- | [[PFSense: | + | ===== References ===== |
- | + | ||
- | [[PFSense: | + | |
- | + | ||
- | [[PFSense: | + | |
- | + | ||
- | [[PFSense: | + | |
- | + | ||
- | [[PFSense: | + | |
- | + | ||
- | [[PFSense: | + | |
- | + | ||
- | [[PFSense: | + | |
- | + | ||
- | [[PFSense: | + | |
- | + | ||
- | [[PFSense: | + | |
+ | https:// |
pfsense/suricata.1610673638.txt.gz · Last modified: 2021/01/15 01:20 by peter