Suricata as inline IPS running on VM from ESXi - Configuration

Would like to hear from anyone that has experience configuring a Suricata IPS inline on a VM hosted on ESXi.

Trying to piece together the network side to ensure the VM is getting the packets from the other VM’s hosted on ESXi, as well as forwarding from a separate subnet of phyiscal machines.

Any feedback or guides would be awesome.

Thanks!

Pretty easy once I found a good guide.

Set VM with 2 nics
Attach VM Network to 1st
Attach Span Network to 2nd

Portgroups:
VM Network - standard settings
Span Network - VLAN ID 4095 & Promisc mode

Test the configuration with a tcpdump -i xxx icmp and then roll our Suricata

2 Likes

Thanks.

Work for me. ESXi 6.7

Regards.

1 Like