Intrusion Detection can't enable IPS

Started by keshan, May 12, 2020, 05:55:31 PM

Previous topic - Next topic
Sorry that I post it in the general section of my post, I later found this section is more appropriate for my question.

I just installed OPNsense on my Proxmox with the NIC passthrough.
The NIC is an old Intel 1000 pt dual NIC card.
The OPNsense VM has 1G of RAM, and when I am trying to config the Intrusion Detection with IPS enable I got

2020-05-12T10:05:49 suricata: [100154] <Error> -- [ERRCODE: SC_ERR_INITIALIZATION(45)] - Engine initialization failed, aborting...
2020-05-12T10:05:49 suricata: [100154] <Error> -- [ERRCODE: SC_ERR_THREAD_INIT(49)] - thread "W#01-em0" failed to initialize: flags 0145
2020-05-12T10:05:49 suricata: [100555] <Error> -- [ERRCODE: SC_ERR_NETMAP_CREATE(263)] - Couldn't register em0 with netmap: Cannot allocate memory
2020-05-12T10:05:49 suricata: [100547] <Error> -- [ERRCODE: SC_ERR_NETMAP_CREATE(263)] - Couldn't register em0 with netmap: Cannot allocate memory
2020-05-12T10:05:49 suricata: [100154] <Warning> -- [ERRCODE: SC_ERR_NO_RULES_LOADED(43)] - 1 rule files specified, but no rule was loaded at all!
2020-05-12T10:05:49 suricata: [100154] <Warning> -- [ERRCODE: SC_WARN_DEFAULT_WILL_CHANGE(317)] - in 5.0 the default for decoder event stats will go from 'decoder.<proto>.<event>' to 'decoder.event.<proto>.<event>'. See ticket #2225. To suppress this message, set stats.decoder-events-prefix in the yaml.
2020-05-12T10:05:49 suricata: [100413] <Notice> -- This is Suricata version 4.1.8 RELEASE


please point me in the right direction, thanks.

never mind, I increased the VM to 2M and problem soled. ;D

Don't forget to mark your double post in general discussions as solved, too.
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR