NFQ IPS mode or AF_PACKET IPS mode?

Is it better to run Suricata in the NFQ IPS mode or AF_PACKET IPS mode? What environment are each suitable for?

Thank you.

  • Use AF_PACKET IPS Mode when you need high performance and resource efficiency, and you have the necessary permissions and constraints to run it as root.
  • Use NFQ IPS Mode when you need more flexibility in packet filtering and want to integrate Suricata with other Netfilter-based tools like iptables. It’s also a good choice for less performance-critical environments.