Table of Contents

PFSense - Suricata - Install Suricata - Have Suricata Monitor the WAN Interface

Navigate to Services → Suricata → Interfaces.

Click Add.

In General Settings:


In Logging Settings:


In EVE Output Settings:


In Alert and Block Settings:


In Performance and Detection Engine Settings:


In Networks Suricata Should Inspect and Protect:


In Alert Suppression and Filtering:


In Arguments here will be automatically inserted into the Suricata configuration:


Set Categories for the WAN Interface to Monitor

Click on WAN Categories.

In Select the rulesets (Categories) Suricata will load at startup:

NOTE: Do not select all categories, as this will produce too many false positives and lots of time to get right.


Start Suricata on WAN

Navigate to Services → Suricata → Interfaces.

Click the start button.


Return to Install Suricata or continue to Have Suricata Monitor the LAN Interface.