Is there any implementation for openwrt an ips / ids like suricata or snort?

A Suricata port has been attempted, but the Rust port was too old and getting in the way. I haven't seen any progress on it for a year or two.

Snort configuration is discussed in detail on this thread. Maybe start at the bottom. I'm in the process of vastly expanding the config file and supporting scripts (see the tarball linked near the end of the thread).

One caveat: you'll need at least a 1GB RAM device to get snort working, it is a huge memory hog. Also it's good if you have a lot of CPU, might work on some high end ARM, but I'd also suggest x86 to be safe.

1 Like