Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - 4Saken

#1
Quote from: franco on May 16, 2022, 08:14:55 AM
Use the development version.. it has suricata-devel package with the v14 API.


Cheers,
Franco

Thanks Franco!
#2
Hi,

Looking for some1 to briefly explain how to enable this function in the current version/options available.

In Opnsense 21.7.5, suricata - netmap api 14 was enabled and together with rss this ran great for me.  ;D

After 21.7.6 netmap api 14 was disabled because of issues. :-\ 

When Opnsense 22.1 was released, i managed to use suricata version from 22.1beta2 archive, which in return gave me netmap api 14 together with rss, and the threads opened the way i wanted, according to my rss queues. I kept this package locked until the latest update. 8)

Later Opnsense versions and the suricata 6.0.5 pkg do not have this function enabled. Because the beta archive has been removed, restoring this function is not easy anymore without the right knowledge, regarding building your own packaged.  ::)

I am wondering if any1 can give me a brief explanation on how to get this working again.

If some1 could point me in the right direction this would be great:D.

I also suspect there might be more people who like to test this function and are facing the same issue.
Some guidance would be appreciated. :)

Any1?
#3
Quote from: alexroz on November 27, 2021, 03:02:52 PM
Yep. I have Suricata on LAN side interfaces.

After upgrade to 21.7.6 i was facing issues where some interfaces became unreachable, also via setting a static ip. Gateway did not respond at all, dhcp did seem to reach the server. verified by the log. But thats was all. There seemed to be, something stuck. :o

I  noticed this on my management interface.

After removing the management interface from suricata it worked again.
After putting the interface back in the config, it worked like it did before, but did not survive a reboot. 

Yesterday i removed all rules from suricata and disabled suricata for ids/ips.
After downloading all rules and enabling ids/ips my issue has been solved!
#4
Hey guys, just reading up on this. I just reverted to. Been having issues with interfaces this way to, after upgrading to 21.7.6.

Did you guys perhaps have suricata running on those interfaces? My issues seem to be resolved when i disable suricata or taking the interface out of the config.

I was experiencing this on the lan side btw, since i dont have suricata on wan side. My lagg interface seems to be doing just fine with suricata enabled.
Sidenote: rss enabled. intel i210.

I suspect this issue to have something to do with.
Suricata 6.0.4 with an additional change for the Netmap API version 14. not sure  :-X