OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: spetrillo on June 01, 2019, 03:19:22 am

Title: Suricata 5 Beta - Can We Upload to OPNSense
Post by: spetrillo on June 01, 2019, 03:19:22 am
Hello all,

Is there an ability to upload a new package, in this case the Suricata 5 beta, so it can be installed via GUI. Does this need to be done via CLI instead?

Thanks,
Steve
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: franco on June 03, 2019, 05:06:37 pm
Hi Steve,

Working on this for 19.1.9 although we won't have suricata-devel package installable with a single click at the moment as the core package will need to be rebuilt from the git repository with the suricata package replaced.


Cheers,
Franco
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: spetrillo on June 03, 2019, 05:23:22 pm
No worries...and thanks for all the efforts. I am learning alot about OPNsense!
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: franco on June 03, 2019, 05:37:04 pm
Ping me after 19.1.9 is out to post instructions here on how to use Suricata 5 package. I have to give it a good testing beforehand to make sure nothing unpleasant happens.


Cheers,
Franco
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: ruggerio on June 04, 2019, 07:59:51 am
as i will be soon happy owner of a apu4, i will join the testing then.
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: spetrillo on June 12, 2019, 04:20:31 am
Hey @franco is it time to test the Suricata 5 install?
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: mimugmail on June 12, 2019, 06:45:16 am
When on 19.1.9:

pkg install suricata-devel
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: ruggerio on June 12, 2019, 07:56:48 am
this will try to uninstall pkg opnsense-19.1.9
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: franco on June 12, 2019, 01:15:30 pm
Switch to development and do an upgrade to install it. Then on the console:

# opnsense-code core
# cd /usr/core
# make upgrade CORE_SURICATA=-devel


Cheers,
Franco
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: ruggerio on June 12, 2019, 08:19:59 pm
thx! on s5 now. just done some testing with eicar, this works quite well.

i had another firewall with ipfire/suricata in parallel - what is astaunishing, this one drops attacks like crazy with the same rule (compromised i think are good for testing)  - whilst i nearly see no attack on opnsense.
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: ruggerio on June 17, 2019, 07:28:50 am
After a few days, i cannot see any difference between 5 beta and 4. Should there be a difference?

All what i've seen so far, CPU is no longer on high load for long time, if downloading e.g. a 2 GB DVD-ISO.
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: ruggerio on June 18, 2019, 03:48:29 pm
After changing some rules today i have the following message:

suricata: [100705] <Warning> -- [ERRCODE: SC_WARN_OPTION_OBSOLETE(233)] - netmap interface igb2+ uses obsolete '+' notation. Using '^' instead

in this case, its the wan-interface. But this comes for all interfaces.

And: get nearly no entries in Alert-log, but having a web- and mailserver with both imap and smtp-rules...). This feels a little bit strange. On Suricata 4 too.



Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: ruggerio on June 21, 2019, 07:19:39 am
still only entries in alarm-tab,  if i test a eicar. Nothing else. I am not sure, if it is working correct. Somebody else perhaps with more reliable results?

btw. i am in IPS-Mode. Will switch now to IDP.
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: ruggerio on June 26, 2019, 07:52:01 am
Still no change - am i the only tester for the moment? When is 5 planned in opnsense for golive?

btw. i deleted all the rules in /usr/local/etc/suricata/rules and ./opnsense-rules, as i got massy of errors of flowbits set. Re-downloaded all the rules i checked, but the errors persist.

Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: mimugmail on June 26, 2019, 11:24:33 am
S5 isn't stable yet, so there are no plans to migrate.
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: ruggerio on June 26, 2019, 12:50:18 pm
so i ask, if it makes sense to test s5 here?
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: mimugmail on June 26, 2019, 01:27:19 pm
Sure it makes sense, maybe it makes sense to switch logging to syslog and check eve.log about S5 findings.
Regarding the interface naming maybe it's worth to check release notes.

Most of the dev's are highly loaded with other tasks, that's why they'll start to test when S5 is stable (my personal view). Nonetheless, very appreciated when you start testing first!  8)
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: ruggerio on June 26, 2019, 01:44:11 pm
OK, can we be sure, that the rulesets e.g. of ET Open are compatible between the versions?
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: mimugmail on June 26, 2019, 02:59:11 pm
I haven't tested them yet, but you should get some warnings in suricata log if they don't fit
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: mimugmail on June 27, 2019, 11:18:24 am
Ok, it seems the logging is broken, but right now I have no idea if it's new logging features of 19.7 or Suricata itself.
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: ruggerio on August 26, 2019, 07:29:17 am
i am quite sure, it's suricata itself, as i stepped down to 4.1. and still have problems with logging. I will now "upgrade" again to suricata 5 and continue testing.
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: ruggerio on August 26, 2019, 07:35:49 am
btw. wouldn't it perhaps make sense, to plan suricata 5 for 20.1?
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: franco on August 27, 2019, 06:07:33 pm
It it's out and it works fine it's in 20.1, maybe even 19.7 later on. It depends on the release date. Probably some time this fall.


Cheers,
Franco
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: spetrillo on October 20, 2019, 05:55:54 pm
It looks like Suricata 5 is now a stable release. Is there a timetable for including it in OPNsense? Version 20 perhaps? Is there also a way to get other options added to the plugins, like Elastic Beats?
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: mimugmail on October 20, 2019, 06:32:49 pm
There is already a pkg for beats :)
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: spetrillo on October 20, 2019, 06:48:31 pm
Yes it is 6.7.1 but needs to be installed manually. Will it ever get added as a plug-in or will it always be manual?
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: mimugmail on October 20, 2019, 10:48:38 pm
I have a kind of enterprise plugin with a pure free field to configure, but it will never be merged.
Title: Re: Suricata 5 Beta - Can We Upload to OPNSense
Post by: spetrillo on October 20, 2019, 11:02:31 pm
That is certainly too bad. I am trying to figure out how to keep Beats up to date on OPNsense. A bit of a pain.