What's new

Suricata Suricata 6 is available for testing

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

It's kind of shocking that this project is not getting more attention. This seems to be THE answer for those with Merlin concerned about sending all our data to Trend Micro. Yea, these routers could use more ram, but multiple people have mentioned no noticeable slowdown. It would be awesome if this could be included in AMTM...
 
It's kind of shocking that this project is not getting more attention. This seems to be THE answer for those with Merlin concerned about sending all our data to Trend Micro. Yea, these routers could use more ram, but multiple people have mentioned no noticeable slowdown. It would be awesome if this could be included in AMTM...
Maybe once the new WiFi 7 routers are released, they could offer enough oomph (2.6GHz quad core processor, 256 MB Flash and 2 GB RAM)
to power Suricata efficiently.
 
Speaking of RAM... Is there anything about the firmware that makes it "physically impossible" to upgrade the internal RAM in these Asus routers? We see people upgrading "non-upgradeable" ram / storage in M1 Macs, and so on. Just because the manufacturer wouldn't recommend it, or just because other users may think "just get a better router" doesn't mean it wouldn't be a fun project for the rest of us. Any way to find out the theoretical max possible RAM in an RT-AX88U for instance?
 
Chip replacement only won't work. You have to dig deeper than firmware in bootloader. I expect it to be model specific. Reverse engineering is needed, nothing is documented. No point doing it - routers are tuned more for power efficiency and the CPUs are weak for true IDS/IPS. You need RAM and CPU.
 
Hi Does this version of suricata use hardware offloading ?

I have a GT-AXE16000

I just install and test it in ips mode: with NFQUEUE

I test some detection like BlackSun user-agent and they are détect and block.
So the suricata seems to do his job.

I still have a near 10gb Throughput (Lan/Wan) and suricata is a less than 1% cpu

And with NFQUEUE iptables rule, i can exclude some interface like vpn ...

Does a package with UI like v4 version is planned ?


Best Regard
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top