In this video, we'll talk about the installation and initial configuration of the Suricata IDS/IPS. Furthermore, we'll present the installation in a gradual and progressive way. This way, it will be possible to repeat the steps described in the video and complete the installation.
Suricata is one of Snort's competitors. However, Snort can also use Snort's rule lists. Some people prefer Snort and others prefer Suricata. I believe the most sensible thing to do is analyze the scenario and, based on that scenario, decide which IDS/IPS to use.
Snort Installation/Configuration on pfSense
• Instalação/configuração do Snort no pfSense
Snort+pfSense: Detecting/Blocking Port Scans on the Network.
• Snort+pfSense: Detectando/Bloqueando Ports...
00:00 Introduction
00:43 Installing Suricata on pfSense
01:17 Configuring Suricata
01:47 Configuring the Suricata interface
02:27 Transforming Suricata into an IPS
03:45 Performance vs. detection rate
04:52 Concepts about Home Net and Ignoring networks
05:45 Creating the Pass List
06:56 Including the Pass List in the Home Net
07:35 Selecting rule repositories
08:55 Time between rule list updates
09:18 Time to remove blocked hosts
09:47 Downloading and installing rule lists
10:23 Starting Suricata on the WAN interface
10:34 Checking Alerts and Blocks
11:02 Deleting a False Positive Rule
11:51 Dashboard with Suricata Alerts
#suricata #suricataIDS #suricataIPS
Presented by Professor Dalbert