Skip to content

Does Sruicata capture SSL/TLS traffic? #14003

Closed Answered by Cantondy
Cantondy asked this question in Q&A
Discussion options

You must be logged in to vote

Hello,

While doing some more research and testing, I came across a post of a similar problem: https://groups.google.com/g/security-onion/c/Qoh9jlOi2_U

According to this post, it seems that the solution is to change the :

vlan
use-for-tracking 

to false.

So I made this change:

  • Go to the GUI under Administration --> Configuration

  • In the Option tab at the top, check show advanced settings

  • Then go to the suricata tab --> config --> vlan --> use-for-tracking and set the value to false

And it actually worked, I'm now able to trigger alerts on SSL/TLS and HTTP traffic (the rule I gave earlier works).

This “vlan-for-tracking” option is used to tell Suricata to identify and track packets …

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@Cantondy
Comment options

@dougburks
Comment options

@Cantondy
Comment options

Answer selected by Cantondy
@dougburks
Comment options

@Cantondy
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants