# \#config

**URL:** https://community.emergingthreats.net/tag/config/7.md

[Latest](https://community.emergingthreats.net/latest.md) · [Categories](https://community.emergingthreats.net/categories.md) · [Tags](https://community.emergingthreats.net/tags.md)

---

## [IDS and IPS rules on LAN](https://community.emergingthreats.net/t/ids-and-ips-rules-on-lan/1300)

<div class="topic-metadata">

**Author:** [@hacked](https://community.emergingthreats.net/u/hacked)\
**Replies:** 1\
**Last updated:** [January 22, 2024, 6:05pm UTC](https://community.emergingthreats.net/t/ids-and-ips-rules-on-lan/1300 "2024-01-22T18:05:41Z")

</div>

Hi, I’m interesting to do IDS and IPS on the inside of my network using Suricata. I have trouble of as an exampe of detecting nmap scans and having a look at the example rule below: alert tcp $EXTERNAL\_NET any → $HOME\_…

---

## [HTTP/2 in Suricata 6](https://community.emergingthreats.net/t/http-2-in-suricata-6/257)

<div class="topic-metadata">

**Author:** [@bmurphy](https://community.emergingthreats.net/u/bmurphy)\
**Replies:** 0\
**Last updated:** [January 10, 2023, 4:56pm UTC](https://community.emergingthreats.net/t/http-2-in-suricata-6/257 "2023-01-10T16:56:57Z")

</div>

While recently working on a malware sample which had some HTTP2 traffic in it. I was surprised that Suricata did not log or alert on any of the traffic for HTTP2, despite having written a rule for the traffic. Turns out…
