Add Suricata IDS to FredOS-Mediaserver

Passive network monitoring via af-packet on eno1. Rulesets auto-updated
from ET/Open, abuse.ch, and other community sources via suricata-update.
Runs alongside fail2ban; IPS/blocking mode can be enabled later.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
ediblerope 2026-04-06 20:36:45 +01:00
parent 2104de314e
commit b91b0ef234
2 changed files with 59 additions and 0 deletions

View file

@ -30,6 +30,7 @@
./services/bazarr.nix
./services/cloudflare-ddns.nix
./services/fail2ban.nix
./services/suricata.nix
];
### Make build time quicker