OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: gctwnl on April 21, 2023, 01:23:09 PM

Title: [SOLVED] Many confusing elements of configuring IDS/IPS (Suricata)
Post by: gctwnl on April 21, 2023, 01:23:09 PM
I keep getting this when trying to save my Suricata download set in Administration. Even deselecting everything and trying to save gets me this. Download & Update rules doesn't help.

I can start suricata, but it says 'no rules are loaded' so it is now completely nonfunctional.

Help?

OPNsense 22.10.2 (Deciso)

Log shows error:
2023-04-21T14:42:01 Warning suricata [100410] <Warning> -- [ERRCODE: SC_ERR_NO_RULES_LOADED(43)] - 2 rule files specified, but no rules were loaded!
Title: Re: Endless "Please use "Download & Update Rules" to fetch your initial ruleset"
Post by: gctwnl on April 21, 2023, 03:14:48 PM
[Removed, it was a red herring]
Title: Re: Endless "Please use "Download & Update Rules" to fetch your initial ruleset"
Post by: gctwnl on April 21, 2023, 03:58:22 PM
Forget it. I have deinstalled and reinstalled the ET Telemetry version and I no longer have this error, but still the frontend Save button for Downloads refuses to work.

Kind of pissed now about losing 7 hours with an OPNsense frontend that suddenly for some unknown reason when I was changing the IDS config has stopped working. I'd like a 'total reset' option for my suricata config. CLI is fine.

It seems OPNsense can get i a state where its frontend UI stops working and als stops creating a usable Suricata config because the 'Save' button won't work. And it seems that state for the UI is permanent and survives whatever you install/deinstall as plugins.
Title: Re: Endless "Please use "Download & Update Rules" to fetch your initial ruleset"
Post by: gctwnl on April 21, 2023, 04:59:57 PM
Remove ET Telemetry Pro and installed ET Open. That one works. The frontend is also different, there is no Save button (for now, who knows what happens when OPNsense gets hosed again here too). Simply update the rules.
Title: Re: Endless "Please use "Download & Update Rules" to fetch your initial ruleset"
Post by: cookiemonster on April 21, 2023, 05:21:19 PM
If I remember correctly the order is 1. select & enable the ruleset(s) 2. Save button 3. Download and update rules.
If ETP Pro is to be used, there is the addtional steps of registration, etc.
That gives you the collections of rules available, and you can move to select them in the policies you have to create. You can use the rules tab but is better to use policies to group them.
I've never seen the Save button disappear. I don't know what might be happening there.
Title: Re: Endless "Please use "Download & Update Rules" to fetch your initial ruleset"
Post by: gctwnl on April 21, 2023, 05:49:08 PM
The Save button does not disappear. What happened is that it was available but when you clicked it it said "Download and Update" first (short time visible message). But if you then Download and Update, this stays.

The result was that I had no rules whatsoever.

But I am starting to suspect that I am misinterpreting the GUI. Save = 'save config", the Download & Update is the next step (to populate). Intuitively (or my intuition at least), the Save button would come at the end (which it normally does). As I did not see any actual rules (and Suricata complained), I concluded Save was failing.

Tomorrow I'm going to retry with ET Telemetry again. ET Open is working, but that one doesn't have a 'Save' button, only the "Download & Update".
Title: SOLVED: Endless "Please use "Download & Update Rules""
Post by: gctwnl on April 22, 2023, 01:13:58 PM
I got ET Open working. I have returned to ET Telemetry and everything is now working. A summary of the things that confused me:

So, the three things mixed here: ET Telemetry comes with a bunch of empty rule sets, turning IPS on doesn't block anything until you change 'alert' to 'block' in a Policy/Policies, and 'Save' is not (as it n romally is' the definitive action to get something working.