Suricata on r7800?

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Author Message
susoq
DD-WRT Novice


Joined: 02 Jun 2022
Posts: 1

PostPosted: Thu Jun 02, 2022 10:01    Post subject: Suricata on r7800? Reply with quote
Hello,

Has anyone installed Suricata (through Entware) on a r7800 router? If so, how was performance (and which rules did you use)?

This is really intriguing to me but I had been assuming that performance of the router would go down tremendously...

Thanks for any info anyone might have!
Sponsor
the-joker
DD-WRT Developer/Maintainer


Joined: 31 Jul 2021
Posts: 2146
Location: All over YOUR webs

PostPosted: Thu Jun 02, 2022 11:44    Post subject: Reply with quote
While it is always nice to have such a fallback, its kind of moot if you dont keep up with the latest dd-wrt versions which fix known CVE's in kernel, libraries and 3rd party components.

Also, Entware packages are rarely kept up-to-date and thus not keeping up with all CVE patches and they are maintained by random 3rd parties whom you need to trust.

Having said that, you could always test installing it and answering your own question, I remember reading anyone doing this.

However and because Im a curious person by nature, I found this https://github.com/spithash/DD-WRT-Update-Suricata-Rules-Automatically so perhaps this person has already tried this, so you could ask them on GitHub, maybe?

_________________
Saving your retinas from the burn!🔥
DD-WRT Inspired themes for routers
DD-WRT Inspired themes for the phpBB Forum
DD-WRT Inspired themes for the SVN Trac & FTP site
Join in for a chat @ #style_it_themes_public:matrix.org or #style_it_themes:discord

DD-WRT UI Themes Bug Reporting and Discussion thread

Router: ANus RT-AC68U E1 (recognized as C1)
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6447
Location: UK, London, just across the river..

PostPosted: Thu Jun 02, 2022 18:39    Post subject: Reply with quote
snort or suricata are made to run only on x86/x64 pc,
On router it will saturate the CPU badly,as it has to scan each packet, especially if you have a higher WAN speeds 500mbt to 1Gig its impossible, but even a lower WAN speeds are too heavy...as well, it depends from its configuration...
but on very low WAN speeds it may work, although not very useful...


as well bear in mind entware is running the older versions, of those... so not much point of entware, your best bet is dedicated PC on WAN...
as alternatives pfsense, OPENsense..much easy to config and understand...

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum