Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

Is Suricata (firewall IPS) overkill for home?

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
1 post • Page 1 of 1
Author
Message
statikregimen
Apprentice
Apprentice
Posts: 173
Joined: Sat Jul 16, 2011 7:31 am
Location: USA/Michigan
Contact:
Contact statikregimen
Website

Is Suricata (firewall IPS) overkill for home?

  • Quote

Post by statikregimen » Thu Oct 01, 2020 1:48 am

Hi all,

I recently purchased a Pfsense firewall (Netgate SG-1100), and have it set mostly at default values, which all seemed sane for my use case (maybe some things I missed or didn't understand, so advice is deeply appreciated). I've test driven Suricata, and it works fine on my device, but I'm also aware of the attention it requires to be effective.

Basic physical topology is Modem -> FW's WAN port...FW's "LAN" port -> internal wifi router's WAN port (ofc I have its firewall turned on as well, and overall I am confident that the device is as locked down as it can be, while still being powered on... It's a Linksys, after all). Clients on the internal wifi router are 2xGentoo laptops, an Android phone, 2xMedia devices, and a Windows desktop.

My home server is on the "OPT" port of the new firewall, which I put on same VLAN as the firewall's "LAN" port, so I can access it directly from the internal LAN. This way, any ports I forward to the server in the future will hopefully be pretty well segregated from my internal LAN.

I also set up the limited (2 ports) VLAN capability of my wifi router, so I can add some home automation stuff to those, which will hopefully help to segregate that traffic as well.

With all of that, I guess what I'm basically asking, is if the work/tuning needed to get the most out of Suricata is worth the reward, or if I'm pretty well covered as I have it now? Again: any other tips/advice are welcome.

Thank you for reading!
Top
Post Reply
1 post • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic