0

I have a interface where traffic is flowing from internet to NGINX server to application server. I want to monitor (IDS) the traffic flowing between Internet and NGINX at L3,4 and IPS the traffic flowing out from NGINX to application server at L3,4,7.

Will it be possible to use same suricata instance to do the both?

masegaloeh
  • 18,236
  • 10
  • 57
  • 106

1 Answers1

0

Not at this time. There is work being done to support this use case using NFQUEUE (IPS) and NFLOG (IDS).

Ticket: https://redmine.openinfosecfoundation.org/issues/1604

But for now you will have to run 2 instances.