OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • [CALL FOR TESTING] Suricata 4.0.0
« previous next »
  • Print
Pages: [1] 2

Author Topic: [CALL FOR TESTING] Suricata 4.0.0  (Read 11460 times)

fabian

  • Hero Member
  • *****
  • Posts: 2768
  • Karma: 199
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
[CALL FOR TESTING] Suricata 4.0.0
« on: July 28, 2017, 08:15:49 pm »
Hi all,

Suricata 4.0 is out and I asked Franco to build it for 17.7. It will not be included in the stable version but it can be installed via the shell by running the following command:

Code: [Select]
pkg install https://pkg.opnsense.org/snapshots/suricata-4.0.0.txz
In a short test it still works without changing the GUI. Note: If you are having Suricata running, you will have to to restart it after installation. You can do that in the GUI.
« Last Edit: August 01, 2017, 10:48:19 am by franco »
Logged

phoenix

  • Hero Member
  • *****
  • Posts: 510
  • Karma: 57
    • View Profile
Re: Suricata 4
« Reply #1 on: July 28, 2017, 09:06:38 pm »
Hi

I've just tried that on my 17.7R2 and got the following:

Code: [Select]
root@OPNsense:~ # pkg install https://pkg.opnsense.org/snapshots/suricata-4.0.0.txz
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
pkg: No packages available to install matching 'https://pkg.opnsense.org/snapshots/suricata-4.0.0.txz' have been found in the repositories
The file does appear in the list if I browse to that address, have I missed something?
Logged
Regards


Bill

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13988
  • Karma: 1211
    • View Profile
Re: Suricata 4
« Reply #2 on: July 28, 2017, 09:07:20 pm »
Almost...

# pkg add -f https://pkg.opnsense.org/snapshots/suricata-4.0.0.txz

Note this package is for amd64, and the current release version can be restored with:

# opnsense-revert suricata


Cheers,
Franco
Logged

phoenix

  • Hero Member
  • *****
  • Posts: 510
  • Karma: 57
    • View Profile
Re: Suricata 4
« Reply #3 on: July 28, 2017, 09:18:03 pm »
Hi Franco

Thanks for that, it worked and is up and running. :) Anything specific in this version that we should be aware of.
Logged
Regards


Bill

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13988
  • Karma: 1211
    • View Profile
Re: Suricata 4
« Reply #4 on: July 28, 2017, 09:26:56 pm »
Hi Bill,

I haven't gone through the list of changes in detail. The port update was very easy, the syntax gave no issues in the yaml, I'd say it's a straight-forward update with small bits of numerous improvements in all areas:

https://github.com/inliniac/suricata/blob/b8428378ac6fb2365337ae765e19dfc0f4548e4a/ChangeLog#L1-L95


Cheers,
Franco
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13988
  • Karma: 1211
    • View Profile
Re: [CALL FOR TESTING] Suricata 4.0.0
« Reply #5 on: August 01, 2017, 10:50:48 am »
I'm hijacking this thread for a general-purpose call for testing. The port was just finished[1]. It seems to work just fine.

To install:

# pkg add -f https://pkg.opnsense.org/snapshots/suricata-4.0.0.txz

To revert:

# opnsense-revert suricata

Don't forget to restart Suricata for the new version to take effect.

Will a few more people on 17.7 amd64 ack/nak this version bump?


Cheers,
Franco

--
[1] https://github.com/opnsense/ports/commit/67e8ed627e
Logged

phoenix

  • Hero Member
  • *****
  • Posts: 510
  • Karma: 57
    • View Profile
Re: [CALL FOR TESTING] Suricata 4.0.0
« Reply #6 on: August 01, 2017, 01:23:59 pm »
Hi Franco

There's a message displayed after the install:

Code: [Select]
You may want to try BPF in zerocopy mode to test performance improvements:

        sysctl -w net.bpf.zerocopy_enable=1

Don't forget to add net.bpf.zerocopy_enable=1 to /etc/sysctl.conf
Is it suggested we apply that or just leave it as-is?
Logged
Regards


Bill

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13988
  • Karma: 1211
    • View Profile
Re: [CALL FOR TESTING] Suricata 4.0.0
« Reply #7 on: August 01, 2017, 02:26:52 pm »
BPF is for PCAP mode (non-IPS). It doesn't hurt to try this setting, if it brings performance gains, but can also be safely ignored.
Logged

phoenix

  • Hero Member
  • *****
  • Posts: 510
  • Karma: 57
    • View Profile
Re: [CALL FOR TESTING] Suricata 4.0.0
« Reply #8 on: August 01, 2017, 03:38:14 pm »
Quote from: franco on August 01, 2017, 02:26:52 pm
BPF is for PCAP mode (non-IPS). It doesn't hurt to try this setting, if it brings performance gains, but can also be safely ignored.
Thanks for that information. I'll try enabling it and see what happens but my server is lightly loaded anyway so I guess I won't see much difference, if any.
Logged
Regards


Bill

Noctur

  • Jr. Member
  • **
  • Posts: 79
  • Karma: 4
    • View Profile
Re: [CALL FOR TESTING] Suricata 4.0.0
« Reply #9 on: August 01, 2017, 10:44:02 pm »
Running for a day now.. Seems to be working similarly to 3.x. Smooth transition.
Logged
overkill: Dell SFF i5, 16gb, 120gb SSD, 4x gb NICs
OPNsense 21.1.x

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: [CALL FOR TESTING] Suricata 4.0.0
« Reply #10 on: August 01, 2017, 11:16:22 pm »
I have a And hardware,
any specific thing to test ?
I can install it on a production with 1 gbps connection
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13988
  • Karma: 1211
    • View Profile
Re: [CALL FOR TESTING] Suricata 4.0.0
« Reply #11 on: August 02, 2017, 06:30:58 am »
Nothing special, just generally looking for positive feedback to upgrade. So far it looks seamless as far as 3.2.3 -> 4.0.0 goes.


Thanks,
Franco
Logged

mw01

  • Newbie
  • *
  • Posts: 31
  • Karma: 4
    • View Profile
Re: [CALL FOR TESTING] Suricata 4.0.0
« Reply #12 on: August 03, 2017, 12:34:12 am »
Upgraded from 17.1.11 to 17.7 and Suricata 4.0.0.  Went smoothly, no issues.  apu2 AMD GX-412TC SOC (4 cores)
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13988
  • Karma: 1211
    • View Profile
Re: [CALL FOR TESTING] Suricata 4.0.0
« Reply #13 on: August 03, 2017, 07:23:41 am »
I'll get an ok from the core team just to be sure... I think it looks good for inclusion in 17.7.1.

Thank you all <3
Logged

xmichielx

  • Newbie
  • *
  • Posts: 44
  • Karma: 0
    • View Profile
Re: [CALL FOR TESTING] Suricata 4.0.0
« Reply #14 on: August 28, 2017, 04:36:52 pm »
Quote from: mw01 on August 03, 2017, 12:34:12 am
Upgraded from 17.1.11 to 17.7 and Suricata 4.0.0.  Went smoothly, no issues.  apu2 AMD GX-412TC SOC (4 cores)

Did you test with bandwidth tests? Find a difference in performance when testing through your APU2? I experienced much better bandwidth performance with 4.* then with the 3.* series of Suricata.
Please let us know if you also experience less of a cap on your bandwidth with Suricata 4.*
Logged

  • Print
Pages: [1] 2
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • [CALL FOR TESTING] Suricata 4.0.0
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2