Hi Peter,
I read that Scirius will soon support configuring the rules in "block" mode. In terms of topology, will this require that the SELKS host is set in bridge mode (the traffic has to go through it) or can it be something like it can be on a monitor port and send disconnects to to the offending sessions.
I currently have mine in bridge mode, it creates a single point of failure (if the SELKS host goes down, no more Internet). I have seen the other setup on other firewalls, where the firewall is not directly in the path of the traffic, but actively kills sessions by sending TCP FINs faking the IP address of the offending host. In that case, if the SELKS host fails, the traffic is no longer protected but keeps flowing.
This is more a Suricata than a Scirius question, I'm trying to grab a better understanding of what the upcoming feature in Scirius will assume about the network topology and the Suricata configuration.
Thanks,
Michel.