Skip to content

Commit

Permalink
intrusion detection: behaviour change in suricata 7
Browse files Browse the repository at this point in the history
  • Loading branch information
fichtner committed Jan 30, 2024
1 parent 890ca64 commit f5ae0c8
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions src/opnsense/service/templates/OPNsense/IDS/suricata.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -1333,6 +1333,8 @@ stream:
checksum-validation: yes # reject wrong csums
inline: {% if OPNsense.IDS.general.ips|default("0") == "1" %}true{% else %}auto{% endif %}
midstream:
midstream-policy: ignore
reassembly:
memcap: 256mb
depth: 1mb # reassemble 1mb into a stream
Expand Down

0 comments on commit f5ae0c8

Please sign in to comment.