OPNsense Forum

Archive => 20.7 Legacy Series => Topic started by: Archanfel80 on August 06, 2020, 03:35:22 pm

Title: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
Post by: Archanfel80 on August 06, 2020, 03:35:22 pm
After upgrade from the latest 20.1.x to the 20.7 the firewall crashed right after the suricata service loaded. Some sort of CPU error, i cant see its scrolling too fast, then immediately reboot the machine. This stuck into a loop.
Full clean 20.7 install then restore the config.xml also cause this issue.
So the problem is with the suricata related part in the config.xml. Or even the whole suricata module bugged.
Make sure you are disabled before the upgrade.
Title: Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
Post by: mb on August 06, 2020, 04:27:13 pm
It's related to netmap. See this thread:

https://forum.opnsense.org/index.php?topic=17363.msg83997#msg83997

Title: Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
Post by: EHRETic on August 07, 2020, 08:56:48 am
Same for me (it's a VM, no VLAN tagging, interface firectly on Internet with public address)

I let the IPS without blocking mode for now. At the second you activate blocking mode, it crashs ;D
Title: Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
Post by: Archanfel80 on August 07, 2020, 09:10:54 am
Yes! Its a vmware VM on my side too, no vlan just native interfaces. As soon as i enabled blocking, the OS crashed and reset, then its stuck in a loop. Its an urgent issue since we use IPS many FW. Im reverted to 20.1 for now.

Same for me (it's a VM, no VLAN tagging, interface firectly on Internet with public address)

I let the IPS without blocking mode for now. At the second you activate blocking mode, it crashs ;D
Title: Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
Post by: mb on August 07, 2020, 06:10:58 pm
A test kernel for 20.7 should be out soon. Till then, it's safe to stay on 20.1.
Title: Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
Post by: W0nderW0lf on August 07, 2020, 06:27:00 pm
I agree with mb.
Tried out 20.1 again and after restoring from backup, everything worked as before.
I also noticed, while looking at the opnsense terminal. Every Browser action on the dashboard, gets instantly stdout to the terminal. This never happened before. Hope we wont have to wait 2 long for a fix. :)

By the way, this bug seems to not only affect VM's since I am running Opnsense on bare metal with Intel chips.
Title: Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
Post by: Archanfel80 on August 07, 2020, 07:54:56 pm
If i understand correctly this is not the opnsense issue but the freebsd and the kernel.
This "hardened" BSD project is a way to overkill for everyday use. Its cause trouble trouble trouble.