OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: Mks on March 04, 2019, 09:36:10 pm

Title: IPS stops working (19.1.2)
Post by: Mks on March 04, 2019, 09:36:10 pm
Hi,

with update to 19.1.2 my IPS stops working.

A lot of warnings in the log, similar to:
Code: [Select]
<Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit
Also the notice are a bit strange because of 0 packets
Quote
suricata: [100234] <Notice> -- Stats for 'pppoe0+': pkts: 0, drop: 0 (nan%), invalid chksum: 0
Code: [Select]
suricata: [100234] <Notice> -- Stats for 'pppoe0': pkts: 0, drop: 0 (nan%), invalid chksum: 0
Any idea?

Thanks

br
Title: Re: IPS stops working (19.1.2)
Post by: rabievdm on March 05, 2019, 11:41:07 am
I'm just checking, but it's a know issue that PPP interfaces don't work with the netmap implementation.
If you are aware and just pointing out the logs then ignore me :)
If you weren't aware, then sadly IPS will not work on a PPP interface and from posts I have seen is likely to never be fixed on BSD.

Either monitor the internal and/or DMZ interface or do you PPPoE upstream or use a different OS (but then you lose the OpnSense goodness :( )
Title: Re: IPS stops working (19.1.2)
Post by: Mks on March 05, 2019, 05:35:04 pm
Hi.

I'm using PPPoE for WAN connection, switched to those setup after upgrading to 19.1.2.
So if I understand correct, IPS ist not supportef for WAN Interfaces with PPPoE?

Br
Title: Re: IPS stops working (19.1.2)
Post by: franco on March 05, 2019, 07:19:45 pm
IPS on top of PPP in general, sorry. IDS works fine.


Cheers,
Franco
Title: Re: IPS stops working (19.1.2)
Post by: crt333 on March 05, 2019, 08:41:06 pm
I don't use PPP and ids/ips isn't recording alerts or generally working, even after upgrading to 19.1.2.

I used to see all kinds of alerts, now the only thing I've seen in the last month is "ET INFO Session Traversal Utilities for NAT (STUN Binding Request)". Even the ProofPoint summary window shows no events for days at a time.
Title: Re: IPS stops working (19.1.2)
Post by: Mks on March 06, 2019, 10:50:31 am
Ok, thanks
Title: Re: IPS stops working (19.1.2)
Post by: ruggerio on June 21, 2019, 07:55:19 am
Is this resolved? I still have flowbit-warnings and nearly no log-entries.