Re: IPFW divert and suricata

2015-07-01 Thread Julian Elischer
On 7/1/15 10:31 PM, Luigi Rizzo wrote: On Wed, Jul 1, 2015 at 3:15 PM, Oliver Humpage wrote: Hello, I hope this is a good list to post this on, I have a feeling the solution is somewhere obscure in the networking layer. I've set up an IPS system, using: * FreeBSD 10.1 (guest OS, plenty of R

Re: IPFW divert and suricata

2015-07-01 Thread Oliver Humpage
On 1 Jul 2015, at 15:31, Luigi Rizzo wrote: > For the latter two, you might be better off using netmap > on vmxnet3 (in emulated mode, also disabling offloads), > and if i remember well a couple of years ago there were > efforts to use ​suricata on top of netmap. > Worst case, you can just use t

Re: IPFW divert and suricata

2015-07-01 Thread Luigi Rizzo
On Wed, Jul 1, 2015 at 3:15 PM, Oliver Humpage wrote: > > Hello, > > I hope this is a good list to post this on, I have a feeling the solution > is somewhere obscure in the networking layer. > > I've set up an IPS system, using: > > * FreeBSD 10.1 (guest OS, plenty of RAM/CPU) > * ESXi 5.5 (host