Community discussions

MikroTik App
 
jamthejame
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 65
Joined: Mon Jan 15, 2018 12:12 pm

IDS Alternative

Fri Mar 09, 2018 3:59 am

Hello guys,

Having the following issue:

Decided to use RB3011, which is an upgrade from RB2011. However, before I had pfSense with Firewall & Snort setup but with time, as with any open-source software you start to notice bugs and options not always doing what they are suppose to. So I decided to move to RB3011, but this time I want to remove pfSense and build ROS to do similar job that pfSense, thus firewall is one this, but my question as follows:

- Is there are alternative to Snort / Suricata for deep pocket inspection on Mikrotik?? # I know some things are possible on Layer 7, but the thing about Snot/Suricate they have rules etc being updated which is more progressive. Is there a way to set something up like that purely on ROS?