Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - jan.stasik

#1
Intrusion Detection and Prevention / Suricata crashing
September 06, 2023, 12:00:32 PM
Hello,
I am Currently running OPNsense 23.4.2, Business Edition, running it on ESXi. After the upgrade to this version Suricata is crashing after some time when is enabled. Here is what i see in logs. VMX1 is my internet facing port.
How can be this fixed? And how to get rid of warnings.

   
2023-09-06T11:56:59   Error   suricata   [107240] <Error> -- [ERRCODE: SC_ERR_FATAL(171)] - opening devname netmap:vmx1/R failed: Invalid argument   
2023-09-06T11:54:11   Warning   suricata   [100483] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol http2 enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.   
2023-09-06T11:54:11   Warning   suricata   [100483] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol http2 enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.   
2023-09-06T11:54:11   Warning   suricata   [100483] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol rdp enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.   
2023-09-06T11:54:11   Warning   suricata   [100483] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol mqtt enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.   
2023-09-06T11:54:11   Warning   suricata   [100483] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol rfb enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.   
2023-09-06T11:54:11   Warning   suricata   [100483] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol sip enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.
#2
Sorry but one more thing...the license...maybe I need to elaborate what i did:
- downloaded community edition, deployed as VM
on esxi
- used for a while, configured, tested the features
- upgraded to 23.7.1
- used and tested bit then decided to go for business edition
- bought subscription
- applied subscription
- restarted FW
- then offered upgrade is for non existent 23.10

If i deploy new machine, what happen with license?

Thanks.
#3
Thank you guys for explanation. I am very short with Opnsense but already amazed...coming from PaloAlto and Juniper...
#4
After deployment of a new 23.4 machine, can I run upgrade to 23.7? I assume this time it was an issue going from community edition to business edition right? can i export config from current 23.7 and restore it on a new 23.4?
#5
Can you please point me how to reinstall live running system back to 23.4? I am running it on esxi.
Thank you.
#6
Hello guys,
I've recently purchased business editon and I am struggling to find how to's or some manual for business edition. I am not able to find information how to configure firewall to use the Opnsense provided blocklists, blacklists and geoIP settings.

I am running 23.7.1, and after applying subscription, I am not able to perform the update as it want to update to version 23.10 which doesnt exists yet under my subscription link. What can I do with that?

Is there any section for business edition?

Thank you so much. Apologize myself, I am new here....

Jan