]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/commit
IDS: Allow to inspect traffic from or to OpenVPN
authorStefan Schantl <stefan.schantl@ipfire.org>
Tue, 17 Dec 2019 12:06:29 +0000 (13:06 +0100)
committerArne Fitzenreiter <arne_f@ipfire.org>
Sun, 29 Dec 2019 19:12:06 +0000 (19:12 +0000)
commit51b63b4186e9a5521437ba65b072e9a0522f1105
tree96c2adea4f68918de49392d92853101d557aa145
parenta1cf33ca8f51a65189df88ec88a2e1b8273d476a
IDS: Allow to inspect traffic from or to OpenVPN

This commit allows to configure suricata to monitor traffic from or to
OpenVPN tunnels. This includes the RW server and all established N2N
connections.

Because the RW server and/or each N2N connection uses it's own tun?
device, it is only possible to enable monitoring all of them or to disable
monitoring entirely.

Fixes #12111.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
html/cgi-bin/ids.cgi
src/initscripts/system/suricata