Actions
Feature #8246
openaf-packet: allow specifying IPS mode on the commandline
Effort:
Difficulty:
Label:
Description
Right now a minimal AF_PACKET IPS setup requires a minimal yaml to declare the interface pairs, cluster-id, etc.
It would be good for testing and QA tasks to be able to run it entirely from the commandline.
Not sure about the syntax. --af-packet=ips:eth1:eth2 of something of that nature. Suricata would then use the default settings, and automatically assign the correct cluster-id's.
No data to display
Actions