I managed to succesfully install GeoIP and Suricata 4.0.5 on OPNsense 19.1
2019-02-13T21:54:45.157026+0100 blocked LAN 213.211.198.62 80 192.168.1.101 57486 OPNsense test eicar virus
user@linuxvm$ rm -f eicar.com.txt ; wget http://www.eicar.org/download/eicar.com.txt 2>/dev/null ; cat eicar.com.txtX5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
There is a patch/fix that will be included in 19.1.2https://github.com/opnsense/core/issues/3211#issuecomment-462835563I haven't tried it myself yet..
Quote from: trigger_hippie on February 14, 2019, 08:29:22 amThere is a patch/fix that will be included in 19.1.2https://github.com/opnsense/core/issues/3211#issuecomment-462835563I haven't tried it myself yet..Works here as well. Suricata did already properly block stuff like inbound SSH scans, but now it also forbids the eicar download.