OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Enabling IDS with or without any rule sets causes router to become unresponsive
« previous next »
  • Print
Pages: [1]

Author Topic: Enabling IDS with or without any rule sets causes router to become unresponsive  (Read 2441 times)

rnicholus

  • Newbie
  • *
  • Posts: 4
  • Karma: 0
    • View Profile
Enabling IDS with or without any rule sets causes router to become unresponsive
« on: February 06, 2019, 04:19:36 am »
I’m running the latest opnsense along with the latest suricata. When I enable IDS with or without enabled rule sets, the available RAM quickly decreases. Once it reaches about 81% used, the web ui and the router become completely unresponsive. I am only able to recover with a hard reboot. Processor is a J1800 w/ 2GB RAM. Intel 1 gig nics.

Any thoughts on what might be causing this? I started out with 18.7, and then quickly upgraded to 19.1. 18.7 was only running for a few hours, with both IDS and IPS enabled (no freeze/RAM issues).
« Last Edit: February 06, 2019, 04:52:22 am by rnicholus »
Logged

bmail

  • Newbie
  • *
  • Posts: 37
  • Karma: 1
    • View Profile
Re: Enabling IDS with or without any rule sets causes router to become unresponsive
« Reply #1 on: February 06, 2019, 09:37:55 am »
Hello,

Not a real answer neither an explanation for your issue, but , try Hyperscan  for pattern research (for suricata).

It could work better with Intel NIC and claim  less ram (at least for my system).
Hope it could help you.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Enabling IDS with or without any rule sets causes router to become unresponsive
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2