Skip to main content
RunBook Academy

← All checklists in OPNsense

Before deploymentSecurity

IDS / Suricata Readiness

15 items ·7 critical ·4 warn ·4 info

Suricata on OPNsense gives the firewall inline visibility into threats that a pure packet filter would let through. The cost is performance: an IPS on a busy WAN can drop packets if it cannot keep up, and a noisy ruleset can drown the operator in alerts. Readiness means choosing IDS vs IPS deliberately, keeping rules current, shipping EVE logs to a SIEM, and having a triage path.

When to use

Use this checklist before Suricata is first enabled on an OPNsense firewall, before flipping an interface from IDS to IPS, and after any rule set change or version upgrade. Re-run it quarterly as a regression check.

How to use

Walk the list while reviewing Suricata settings, the rule sets, and the SIEM ingestion. Measure CPU impact during a baseline and a peak window, decide IDS vs IPS per interface, and capture the decision in the change record.

Critical7 items

  1. Services > Intrusion Detection > Administration.
  2. Services > Intrusion Detection > Download Rules.
  3. Services > Intrusion Detection > Advanced; "Eve JSON Log" on.

Warning4 items

  1. Services > Intrusion Detection > Rules; "custom.rules" tab.

Info4 items

  1. Services > Intrusion Detection > Administration; Alerts tab.