Can we run suricata in IDS mode with NFQ support

Please include the following information with your help request:

  • Suricata version
  • Operating system and/or Linux distribution
  • How you installed Suricata (from source, packages, something else)

Hi,

Suricata version - 7.0.7
Operating System - Ubuntu 22.04
Installed suricata from a package.

I have a requirement to run suricata with nfq in ids mode.
I am running suricata with --simulate-ips option in command line to run in IPS mode.
Without this option (–simulate-ips) if we run suricata with “suricata -Dc /etc/suricata/suricata.yaml -q 0” and action as drop it should not drop.
Can anyone suggest how we can run suricata with IDS in nfq support.

Thanks in advance for helping.

Can you share your suricata.yaml config and how you run Suricata? Ideally also at stats.log and suricata.log.