How best to mirror traffic from Network
How best can I mirror traffic from the network interface to an Intrusion Detection System (IDs)? Am thinking of set up Suricate as the intrusion detection system on a dubian server, which will also function as the router. The IDs will only process packets destined for the host. Will this work? If this does not work, what other approach can I use in mirroring the traffic and sending the mirrored traffic to the IDs?