I’am using Suricata in mode IPS, my intention is use run mode “accept”, directioning traffic via firewall for multi queues, that is, it doesn’t matter which interface the packet enters or leaves
My main question is if need setting really one session “af-packet” by interface in my suricata.yaml?
Other question is about cluster-id, what a problem in using same id for all interfaces?
- Suricata v6.0.13
- OS: Debian