Project

General

Profile

Actions

Feature #5148

open

IPS mode for Napatech Card

Added by Chatak Kumar 7 months ago. Updated 7 months ago.

Status:
Resolved
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Hi Team , Suricata only support napatech with IDS mode
and there is no other way around with napatech cards to make it run IPS mode

So I request you to add IPS functionality with napatech as napatech configuration in suricata.yaml allows inline option
in that way I can receive data from 1 port , drop alerts , and move data out from port 2.

Thanks

Actions #1

Updated by Victor Julien 7 months ago

  • Assignee changed from Jeff Lucovsky to Phil Young
  • Priority changed from Urgent to Normal

The Napatech integration is maintained by Napatech, so please contact them to see if they are interested in addressing this.

Actions #2

Updated by Chatak Kumar 7 months ago

Victor Julien wrote in #note-1:

The Napatech integration is maintained by Napatech, so please contact them to see if they are interested in addressing this.

Asked in their support , seems to inactive

Actions #3

Updated by Phil Young 7 months ago

  • Status changed from New to Resolved
  • Assignee changed from Phil Young to Chatak Kumar

This functionality is already part of the Napatech Capture Method; and has been for some time. Please see the section on "Inline Operation" in https://github.com/OISF/suricata/blob/master/doc/userguide/capture-hardware/napatech.rst. If you need further support please send an e-mail to and someone will help you with the configuration.

Actions #4

Updated by Chatak Kumar 7 months ago

I hope you are talking about IPS mode , because suricata team member said it support only IDS or NSM

Actions

Also available in: Atom PDF