Suricata on OPNsense gives the firewall inline visibility into threats that a pure packet filter would let through. The cost is performance: an IPS on a busy WAN can drop packets if it cannot keep up, and a noisy ruleset can drown the operator in alerts. Readiness means choosing IDS vs IPS deliberately, keeping rules current, shipping EVE logs to a SIEM, and having a triage path.
When to use
Use this checklist before Suricata is first enabled on an OPNsense firewall, before flipping an interface from IDS to IPS, and after any rule set change or version upgrade. Re-run it quarterly as a regression check.
How to use
Walk the list while reviewing Suricata settings, the rule sets, and the SIEM ingestion. Measure CPU impact during a baseline and a peak window, decide IDS vs IPS per interface, and capture the decision in the change record.