Suricata with multiple interfaces

We are running Suricata 7.0.3 on an Ubuntu server with multiple interfaces. Currently, we are testing with /24 subnets, but in the future, we plan to monitor a larger part of our organization, possibly using /16 subnets.

First, we would like to ask if you have any recommendations. Right now, each subnet is configured on a separate interface on the virtual server. Would it be better to have all the traffic on one interface? Does this depend on the capacity of the virtual network card or the amount of traffic being monitored?

Second, is there a limit to the number of interfaces Suricata can monitor?

Thank you.

The subnet size is irrelevant for Suricata (more or less) it is only interested in the actual network traffic, which can be even bigger networks.

Is there a reason to configure it that complicated? It would be much easier to have it on one interface or at least less. This keeps the overhead low and would help performance.

There might be a theoretical limit to Suricata but this is more limited by the NICs or the OS I guess.

1 Like