Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Qu0th

#1
Quote from: vijvis on January 30, 2022, 11:23:12 AM
Running 22.1 on a Protectli Mini PC. I got the error as well upon enabling IPS. Didn't get the error when running in IDS mode. Rebooting the device seems to have fixed it for me and IPS is running normally.

I have the same exact setup and error.
#2
I've had the exact same experience.

Quote from: chemlud on November 29, 2021, 02:25:48 PM
I updated to 21.7.6 yesterday in the evening, this morning hell broke loose on the most important interface (suricata in IPS mode running on a total of 3 interfaces). All of the sudden no internet connection, dhcp delivers addresses, but devices are not reachable on the same LAN.

I rebooted, changed the physical interface (network card), I moved the whole network to another 21.7.6 install, I changed ALL dumb switches on the network, it helps for an hour and then the terror starts again. I have no idea where to start, nothing remarkable in the system log, dhcp log, unbound log, suricata log.

dmesg appended....
#3
On two separate firewalls I have "deny unknown clients" enabled for all subnets. This has been working fine for a long time. With this new update after rebooting, firewall clients are connected for about 45 minutes then all are denied. Reboot and I get another roughly 45 minutes then denied. I have been forced to disable the setting.

Edit: The network still goes down but much less and seems to be related to using the site to site wireguard tunnel. When I hammer that network it tends to hang and need a reboot. It renamed the Wireguard firewall rules section to "Wireguard(group)", oddly.

edit: screw this, I'm reverting to previous version. Maybe don't push out updates over thanksgiving that break things.