Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
IPS mode freezing OPNsense
« previous
next »
Print
Pages: [
1
]
Author
Topic: IPS mode freezing OPNsense (Read 1903 times)
morphxyz
Newbie
Posts: 15
Karma: 1
IPS mode freezing OPNsense
«
on:
December 09, 2023, 03:37:01 pm »
I have Suricata enabled. I get the Alerts and everything works as expected.
As soon i turn on IPS mode, the complete OPNsense machine freezes.
Has anyone experienced that before? What was your solution?
Hardware CRC, TSO and LRO disabled. NO vlan hardware filtering.
I have tried different Pattern matchers and promiscuous mode.
I tried to delete custom tunables aswell:
net.isr.maxthreads=-1
net.isr.dispatch=deferred
net.isr.bindthreads=1
with no luck.
Ryzen 7700 with a bnxt card and driver.
I wonder if it has anything to do with the driver.. I load it with a tuneable "if_bnxt_load=YES"
I see no errors in the log files in the frontend. Guess the logging freezes too.
I can mount the zfs pool and edit the config.xml file to disable IPS mode and everything works as expected, again! But I'd really like to use suricata in IPS mode, obviously so..
Any help or ideas appreciated!
Logged
JL
Newbie
Posts: 42
Karma: 1
Re: IPS mode freezing OPNsense
«
Reply #1 on:
January 16, 2024, 06:01:25 pm »
don't try tuning network cards
unless somehow the driver is very broken and the system deadlocks there should be output in /var/log for causing the freeze
did you try inserting a different network card ?
bnxtload suggest this is a server network card with multiple nic ?
since you mention the ZFS pool, is this by any chance opnsense running in a VM ?
«
Last Edit: January 27, 2024, 10:26:52 pm by JL
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
IPS mode freezing OPNsense