I seem to have similar issues. The firewall seems to be still up & running, but it seems to shut out everything. The issue reminds me of the "new" startup behavior with divert-to rules: all traffic is dropped until the Suricata service is up & running. But this is happening after a day of uptime and the service (probably) up. In the suricata logs I found these errors:
Error
suricata
[100216] <Error> -- thread W-8000 failed
Warning
suricata
[101690] <Warning> -- Write to ipfw divert socket failed: No buffer space available
I'm not sure what buffer space ran out. mbufs seemed to be fine when checking the health graph in reporting. I'm running with kern.ipc.nmbclusters = 1000000
Unfortunately I just upgraded the system on the weekend from the rock solid 25.7.11. I also did the rules migration and migrated Suricata to the new divert-to functionality. So many moving parts changed in just a few days.
To me the problem "feels" to be firewall related so my first mitigation attempt is to revert the divert-to changes back to netmap for now.
I'm using a Protectli FW2B on CoreBoot with an Intel Celeron J3060
Error
suricata
[100216] <Error> -- thread W-8000 failed
Warning
suricata
[101690] <Warning> -- Write to ipfw divert socket failed: No buffer space available
I'm not sure what buffer space ran out. mbufs seemed to be fine when checking the health graph in reporting. I'm running with kern.ipc.nmbclusters = 1000000
Unfortunately I just upgraded the system on the weekend from the rock solid 25.7.11. I also did the rules migration and migrated Suricata to the new divert-to functionality. So many moving parts changed in just a few days.
To me the problem "feels" to be firewall related so my first mitigation attempt is to revert the divert-to changes back to netmap for now.
I'm using a Protectli FW2B on CoreBoot with an Intel Celeron J3060
"