OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: opnrules on August 03, 2020, 09:31:53 pm

Title: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: opnrules on August 03, 2020, 09:31:53 pm
Two seperate issues with similar but slightly different Errors (1).

I can download the rules without a problem and have them all set to drop.
After I intstalled the non commercial rule from the plugins, Error reconfiguring IDS: Error (1) started to occure.

I've since removed that package but the issue persists whenever I download & update rules or make any other change to the settings. Since this started the Rules tab just loads but never shows any results.The IDS however seems to be running.

The other problem I have (and had before above started) is that I also get Error (1) when selecting Hyperscan instead of default.

Is there a way to purge/reset the IDS completely? Could this be related to low memory? Any ideas how to fix this?
Searches for Error (1) in this forum did not yield any results.

Thanks for any suggestions.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: bunchofreeds on August 04, 2020, 09:07:06 am
Not sure this is any help, but I run OPNsense as a VM on Proxmox.

I believe Hyperscan is for Intel Architecture CPU's so will only run successfully against those.

When I select a non Intel type CPU for my OPNsense VM via Proxmox and select Hyperscan, I will get Error (1).

Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: hushcoden on August 04, 2020, 10:25:24 am
I'm actually using Hyperscan with my AMD GX-412TC and it works, no errors so far...
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: W0nderW0lf on August 06, 2020, 07:50:40 pm
I have the same issue. Still trying to figure out, why suricata has that much issues with rules since 20.7
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: spetrillo on August 08, 2020, 06:12:11 pm
I am running an Intel 210 and i350 NICs and am getting the error in 20.7.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: hsimah on August 15, 2020, 04:05:52 pm
Any update on this as I am having the same issue, and started after installing the non-commercial rules plugin.

Code: [Select]
Error reconfiguring IDS
error installing ids rules (Error (1))
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: XeroX on August 23, 2020, 12:06:24 am
I am running an Intel 210 and i350 NICs and am getting the error in 20.7.

These are network cards, Hyperscan is CPU related.

@opnrules
Hardware specs?
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: athurdent on August 26, 2020, 01:58:39 pm
Same problem here with ET telemetry edition. Rule download ends in Error (1).
Suricata seems to work though, got fresh alarms today.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: karaman on September 02, 2020, 08:40:50 am
Same problem
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: malac on September 03, 2020, 09:16:37 am
same error!
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: malac on September 03, 2020, 09:26:04 am
i'll unchecked all interfaces and afterwards checked it again. Now the error is gone....
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: karaman on September 03, 2020, 09:36:45 am
i tried to uncheck all interfaces and checkt again but the error still exists
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: malac on September 03, 2020, 09:42:01 am
i used "clear all" perhaps this matters???
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: athurdent on September 03, 2020, 09:52:36 am
No luck unchecking or using clear either, error persists.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: malac on September 03, 2020, 09:57:33 am
ok, first i reinstalled the surricata package, but the error still exist.
then i used "clear all" and the error was gone
perhaps it was just good luck....
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: karaman on September 03, 2020, 10:40:41 am
New Error Message
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: karaman on September 05, 2020, 07:21:48 pm
Any fixes for this error?
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: Markoh on September 08, 2020, 10:36:37 pm
I had the same Problems to download the rules.

I disabled Suricata and then i deleted all Directories and Files under /usr/local/etc/suricata/opnsense.rules/
reload the config-page and activate ids, then download the rules and all works fine.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: athurdent on September 09, 2020, 08:20:25 am
Removing os-intrusion-detection-content-pt-open-1.0 fixed it for me, I am solely using the ET Telemetry ruleset now without problems it seems.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: mimugmail on September 13, 2020, 08:03:53 pm
To me this happend when IDS process was not running:
https://github.com/opnsense/core/issues/4346

This means that the action worked in general but after this it tries to restart the process which fails, but the reload of rules works
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: karaman on September 27, 2020, 01:29:07 am
I updated to 7.3

The problem is still not corrected. There are errors when updating Suricata rules.

It there any solution?
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: mimugmail on September 27, 2020, 08:14:52 am
configd.log please when error appears
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: l0stnyc on September 27, 2020, 08:12:25 pm
So I am not sure if it is related, but I was also having problems when rules were being reloaded every night via cron.  At first I thought it was the abuse.ch rulesets, so I loaded smaller groups of rulesets at a time, it would only fail on the ET rulesets.  So I am not sure if this an issue on ET's end but in the meantime I've just learned to live with it.  Sometimes it works some nights it doesn't.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: jimjohn on April 27, 2021, 12:20:38 pm
Still got the same problem with the newest OPNsense version. Any update how to fix that?
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: alexcccp on December 20, 2021, 02:31:50 am
Exactly the same error, but IDS works.

the error disappears after deletion
rm -rf / usr/local/etc/suricata/

BUT!  >:(
IDS stops working immediately after enabling ClamAV + ICAP.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: mimugmail on December 20, 2021, 06:22:32 am
Because you have to few RAM? Clamav needs 2gb alone.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: alexcccp on December 20, 2021, 11:22:29 pm
Because you have to few RAM? Clamav needs 2gb alone.


Yes, it’s out of memory!
I have enabled all IDS  rules for the test.
Perhaps there is a recommendation for the minimum settings for the IDS rules?
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: mimugmail on December 21, 2021, 06:54:52 am
I would never use it with less than 8
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: jimjohn on December 26, 2021, 01:06:36 pm
Issue still persists, Suricata quits periodically over night (even when there is nearly no traffic).
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: mimugmail on December 26, 2021, 05:53:24 pm
Are you on 21.7.7?
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: jimjohn on December 26, 2021, 10:41:26 pm
Yes.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: Bogotrax on January 20, 2022, 01:43:29 pm
Exactly the same error, but IDS works.

the error disappears after deletion
rm -rf / usr/local/etc/suricata/

BUT!  >:(
IDS stops working immediately after enabling ClamAV + ICAP.

Where do you apply rm - is there a terminal through the webinterface where you can do this?
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: Julien on January 23, 2022, 04:40:38 pm
ok, first i reinstalled the surricata package, but the error still exist.
then i used "clear all" and the error was gone
perhaps it was just good luck....
i am having the same issue with one box, what do you mean with clear all?
Thank you
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: yeraycito on January 28, 2022, 02:40:40 pm
On a clean install of Opnsense 22.1 the error still appears.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: jimjohn on January 28, 2022, 03:40:17 pm
Could it be memory related? Not enough memory on low-power boxes?
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: yeraycito on January 28, 2022, 03:51:13 pm
No, I have on my Opnsense mini-pc 8 GB of memory. Opnsense + Suricata take up 15% of memory.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: vijvis on January 30, 2022, 11:23:12 am
Running 22.1 on a Protectli Mini PC. I got the error as well upon enabling IPS. Didn't get the error when running in IDS mode. Rebooting the device seems to have fixed it for me and IPS is running normally.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: Qu0th on February 06, 2022, 01:54:43 am
Running 22.1 on a Protectli Mini PC. I got the error as well upon enabling IPS. Didn't get the error when running in IDS mode. Rebooting the device seems to have fixed it for me and IPS is running normally.

I have the same exact setup and error.
Title: Re: Error reconfiguring IDS: Error (1) / Hyperscan: Error installing ids rules (1)
Post by: jkellerer on November 25, 2023, 02:25:08 pm
Had the issue today as well after modifying policies. Added a "%" in the policy description and this broke regeneration of rules. Removing "%" fixed it.

Since sqlite is used in the backend, I assume the policy descriptions are not properly escaped and can break SQL statements if certain characters are used. It may not be the only reason for this error but it is one possible cause.