1
Intrusion Detection and Prevention / Enable IPS prevents DHCP on VLANs
« on: August 26, 2021, 05:10:56 pm »
I'm running 21.7.1
I've been using suricata for a couple years. Originally, I had no VLANs and ran a pretty flat network. I recently redid my network and added an AP that supports VLANs. It it connected to its own interface on my router PC, my wired switch connects to another interface. I am running several VLANs on the WLAN. I realized yesterday that I never enabled suricata on the network port (igb) that the AP is on, so I did that yesterday. Everything on a Wifi VLAN broke.
Details I have since found:
As I was writing this I realize that it looks like dhcpd is trying to assign clients on the VLANs an address for the physical subnet for that port and then the client can't use that IP because it is for the wrong network.
Is there some settings I need to tweak somewhere?
I've been using suricata for a couple years. Originally, I had no VLANs and ran a pretty flat network. I recently redid my network and added an AP that supports VLANs. It it connected to its own interface on my router PC, my wired switch connects to another interface. I am running several VLANs on the WLAN. I realized yesterday that I never enabled suricata on the network port (igb) that the AP is on, so I did that yesterday. Everything on a Wifi VLAN broke.
Details I have since found:
- Things are only broken if IPS is enabled
- Things are still broken even with no rules with IPS enabled
- clients are not able to get a DHCP address assigned.
As I was writing this I realize that it looks like dhcpd is trying to assign clients on the VLANs an address for the physical subnet for that port and then the client can't use that IP because it is for the wrong network.
Is there some settings I need to tweak somewhere?