Suricata IPS with Bypass Switch Recommendatiton
We recently configured the Suricata in IPS mode. The IPS mode was installed on the bridged system. However, we are experiencing some issue when Suricata stop, interrupted and shutdown. It start forwarding the traffic and due to that we often have production down issue. To encountered this we are planning to introduce a bypass switch which will bypass the traffic encase suricata stop functioning. However, before we buy the product we need following information:
Do you recommend any bypass switch which works best with Suricata ( All does the same but encase if you have any preferred device)?
Suricata on Bridge mode. (Are we using the right way or is there any best recommended way you can suggest)
We are using Ubuntu as a OS platform and using bridge utility. DO you recommend anything else?
Will appreciate if anyone respond to these queries. Thanks in advance.