I am running Suricata 6.0.4. I have used version 5.0 previously with an iptables front end, for IDS and bridged two interfaces.
Can I use the iptables (INPUT/FORWARD/OUTPUT) rules for a front end to Suricata in IPS Mode (non-bridged interfaces)? I have Suricata running in AF-Packet IPS mode, but no traffic comes through the iptables. Why?
I have found tht IPTables is not reporting the actual activities for each of the rules in the INPUT, OUTPUT and FORWARDING sections. This made me second guess the actual fundctioning of Suricata, when the issue is really the reporting from IPTables.