I am currently deploying a suricata machine in my virtual network (IDS mode, ubuntu server 20.04 OS). It works fine, when I let suricata listen on the interface “ens33”, which is the interface with a valid network connection and IP address from the DHCP server. However, I need to rewrite some of the network packets (don’t ask why, I just need to). After rewriting I send them from ens33 to a dummy interface “loop1”.
But, when I edit my suricata config (yaml) and set loop1 as the interface suricata should listen on, it triggers none of the rules, while listening on ens33 does trigger alerts.
I cannot find anything about Suricata IDS not supporting listening on a dummy interface. What am I doing wrong?