Enable and Tune Suricata IDS/IPS on pfSense
Suricata is a deep-packet inspection engine. In IDS mode it watches a copy of the traffic on an interface and raises alerts; in IPS mode it actively blocks hosts or drops packets that match a rule. That second mode is the dangerous one: a noisy or badly tuned rule can block a legitimate host — including your own management workstation — and cut production traffic. Treat this as a change to a live firewall, not a lab toy.













