OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Suricata 5 Beta - Can We Upload to OPNSense
« previous next »
  • Print
Pages: [1] 2

Author Topic: Suricata 5 Beta - Can We Upload to OPNSense  (Read 9884 times)

spetrillo

  • Hero Member
  • *****
  • Posts: 721
  • Karma: 8
    • View Profile
Suricata 5 Beta - Can We Upload to OPNSense
« on: June 01, 2019, 03:19:22 am »
Hello all,

Is there an ability to upload a new package, in this case the Suricata 5 beta, so it can be installed via GUI. Does this need to be done via CLI instead?

Thanks,
Steve
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17703
  • Karma: 1616
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #1 on: June 03, 2019, 05:06:37 pm »
Hi Steve,

Working on this for 19.1.9 although we won't have suricata-devel package installable with a single click at the moment as the core package will need to be rebuilt from the git repository with the suricata package replaced.


Cheers,
Franco
Logged

spetrillo

  • Hero Member
  • *****
  • Posts: 721
  • Karma: 8
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #2 on: June 03, 2019, 05:23:22 pm »
No worries...and thanks for all the efforts. I am learning alot about OPNsense!
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17703
  • Karma: 1616
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #3 on: June 03, 2019, 05:37:04 pm »
Ping me after 19.1.9 is out to post instructions here on how to use Suricata 5 package. I have to give it a good testing beforehand to make sure nothing unpleasant happens.


Cheers,
Franco
Logged

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #4 on: June 04, 2019, 07:59:51 am »
as i will be soon happy owner of a apu4, i will join the testing then.
Logged

spetrillo

  • Hero Member
  • *****
  • Posts: 721
  • Karma: 8
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #5 on: June 12, 2019, 04:20:31 am »
Hey @franco is it time to test the Suricata 5 install?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #6 on: June 12, 2019, 06:45:16 am »
When on 19.1.9:

pkg install suricata-devel
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #7 on: June 12, 2019, 07:56:48 am »
this will try to uninstall pkg opnsense-19.1.9
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17703
  • Karma: 1616
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #8 on: June 12, 2019, 01:15:30 pm »
Switch to development and do an upgrade to install it. Then on the console:

# opnsense-code core
# cd /usr/core
# make upgrade CORE_SURICATA=-devel


Cheers,
Franco
Logged

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #9 on: June 12, 2019, 08:19:59 pm »
thx! on s5 now. just done some testing with eicar, this works quite well.

i had another firewall with ipfire/suricata in parallel - what is astaunishing, this one drops attacks like crazy with the same rule (compromised i think are good for testing)  - whilst i nearly see no attack on opnsense.
Logged

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #10 on: June 17, 2019, 07:28:50 am »
After a few days, i cannot see any difference between 5 beta and 4. Should there be a difference?

All what i've seen so far, CPU is no longer on high load for long time, if downloading e.g. a 2 GB DVD-ISO.
Logged

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #11 on: June 18, 2019, 03:48:29 pm »
After changing some rules today i have the following message:

suricata: [100705] <Warning> -- [ERRCODE: SC_WARN_OPTION_OBSOLETE(233)] - netmap interface igb2+ uses obsolete '+' notation. Using '^' instead

in this case, its the wan-interface. But this comes for all interfaces.

And: get nearly no entries in Alert-log, but having a web- and mailserver with both imap and smtp-rules...). This feels a little bit strange. On Suricata 4 too.



Logged

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #12 on: June 21, 2019, 07:19:39 am »
still only entries in alarm-tab,  if i test a eicar. Nothing else. I am not sure, if it is working correct. Somebody else perhaps with more reliable results?

btw. i am in IPS-Mode. Will switch now to IDP.
« Last Edit: June 21, 2019, 08:00:10 am by ruggerio »
Logged

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #13 on: June 26, 2019, 07:52:01 am »
Still no change - am i the only tester for the moment? When is 5 planned in opnsense for golive?

btw. i deleted all the rules in /usr/local/etc/suricata/rules and ./opnsense-rules, as i got massy of errors of flowbits set. Re-downloaded all the rules i checked, but the errors persist.

Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #14 on: June 26, 2019, 11:24:33 am »
S5 isn't stable yet, so there are no plans to migrate.
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1] 2
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Suricata 5 Beta - Can We Upload to OPNSense
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2