<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>RouterOS on nagg.eu</title><link>https://nagg.eu/tags/routeros/</link><description>Recent content in RouterOS on nagg.eu</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sat, 21 Jan 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://nagg.eu/tags/routeros/index.xml" rel="self" type="application/rss+xml"/><item><title>Mikrotik RouterOS WAN traffic sniff Suricata IDS</title><link>https://nagg.eu/mikrotik-routeros-wan-traffic-sniff-using-suricata-ids/</link><pubDate>Sat, 21 Jan 2023 00:00:00 +0000</pubDate><guid>https://nagg.eu/mikrotik-routeros-wan-traffic-sniff-using-suricata-ids/</guid><description>&lt;p&gt;Preface: this is the poor&amp;rsquo;s man way of hooking up Suricata IDS to &lt;del&gt;Mikrotik&lt;/del&gt;
any router.&lt;br&gt;
Better ways would be using port mirroring or putting Suricata host directly
in front of the router.&lt;/p&gt;
&lt;p&gt;My goal was to have all network traffic coming and going from internet
&lt;code&gt;mirrored&lt;/code&gt; into the suricata virtual machine.&lt;br&gt;
Network schema is the following:&lt;br&gt;
(internet) &amp;lt;-&amp;gt; routeros &amp;lt;-&amp;gt; debian_hypervisor &amp;lt;-&amp;gt; (linux bridge) &amp;lt;-&amp;gt; Suricata_VM&lt;/p&gt;
&lt;p&gt;There are few ways of doing this, the one which is in my opinion the lesser
evil involves:&lt;/p&gt;</description></item></channel></rss>