I´ve added a commit for the latest suricata release and you´ll soon be able to give it a try if you´re running a IPFire 3.x early build. Feel free to download the latest emerging rules or use oinkmaster instead.
Give it a try and feel free to contact me, we´ll need support for setting up inline ids features which are a great improvement regarding to snort running on IPFire 2.x
If you´re willing to test suricata without the inline mode (the way IPFire 2.x works) just set up -i red0 for running on the interface and only log alert. Inline mode only works with using NFQUEUE.
Posted: November 11, 2011 • 526 views