diff --git a/src/opnsense/service/templates/OPNsense/IDS/suricata.yaml b/src/opnsense/service/templates/OPNsense/IDS/suricata.yaml index b1bc0efc9b8..7eafa218d8d 100644 --- a/src/opnsense/service/templates/OPNsense/IDS/suricata.yaml +++ b/src/opnsense/service/templates/OPNsense/IDS/suricata.yaml @@ -1333,6 +1333,7 @@ stream: checksum-validation: yes # reject wrong csums inline: {% if OPNsense.IDS.general.ips|default("0") == "1" %}true{% else %}auto{% endif %} + midstream-policy: ignore reassembly: memcap: 256mb depth: 1mb # reassemble 1mb into a stream