I have now changed from Divert (IPS) to Netmap (IDS) and let it run for 24-36h and now tried a normal reboot and at least this time it rebooted normally.
Only took a few seconds for suricata PID to stop and continue with rest of the shutdown/reboot.
I will keep this under wrap and test it again in a few days.
If it now is Divert setting that causes it, we need to try to find the culprit.
I will try to revert to Divert (IPS) and see if I could reproduce and then use a bunch of hopefully good commands to debug.
//Dan Lundqvist
Only took a few seconds for suricata PID to stop and continue with rest of the shutdown/reboot.
I will keep this under wrap and test it again in a few days.
If it now is Divert setting that causes it, we need to try to find the culprit.
I will try to revert to Divert (IPS) and see if I could reproduce and then use a bunch of hopefully good commands to debug.
//Dan Lundqvist
"