I am also running into this issue about every 3 days, and it kills all traffic with divert rules until I manually restart the Suricata service.
Currently running most recent stable version
OPNsense 26.1.3-amd64
Most recent example:
2026-03-08T18:34:56-07:00 Error suricata [101733] <Error> -- thread W-8000 failed
2026-03-08T18:34:56-07:00 Warning suricata [103270] <Warning> -- Write to ipfw divert socket failed: Permission denied
I've resorted to disabling divert mode until root cause can be identified and worked out
Currently running most recent stable version
OPNsense 26.1.3-amd64
Most recent example:
2026-03-08T18:34:56-07:00 Error suricata [101733] <Error> -- thread W-8000 failed
2026-03-08T18:34:56-07:00 Warning suricata [103270] <Warning> -- Write to ipfw divert socket failed: Permission denied
I've resorted to disabling divert mode until root cause can be identified and worked out
"