OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • IPS stops working (19.1.2)
« previous next »
  • Print
Pages: [1]

Author Topic: IPS stops working (19.1.2)  (Read 4785 times)

Mks

  • Sr. Member
  • ****
  • Posts: 272
  • Karma: 19
    • View Profile
IPS stops working (19.1.2)
« on: March 04, 2019, 09:36:10 pm »
Hi,

with update to 19.1.2 my IPS stops working.

A lot of warnings in the log, similar to:
Code: [Select]
<Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit
Also the notice are a bit strange because of 0 packets
Quote
suricata: [100234] <Notice> -- Stats for 'pppoe0+': pkts: 0, drop: 0 (nan%), invalid chksum: 0
Code: [Select]
suricata: [100234] <Notice> -- Stats for 'pppoe0': pkts: 0, drop: 0 (nan%), invalid chksum: 0
Any idea?

Thanks

br
Logged

rabievdm

  • Newbie
  • *
  • Posts: 30
  • Karma: 2
    • View Profile
Re: IPS stops working (19.1.2)
« Reply #1 on: March 05, 2019, 11:41:07 am »
I'm just checking, but it's a know issue that PPP interfaces don't work with the netmap implementation.
If you are aware and just pointing out the logs then ignore me :)
If you weren't aware, then sadly IPS will not work on a PPP interface and from posts I have seen is likely to never be fixed on BSD.

Either monitor the internal and/or DMZ interface or do you PPPoE upstream or use a different OS (but then you lose the OpnSense goodness :( )
Logged

Mks

  • Sr. Member
  • ****
  • Posts: 272
  • Karma: 19
    • View Profile
Re: IPS stops working (19.1.2)
« Reply #2 on: March 05, 2019, 05:35:04 pm »
Hi.

I'm using PPPoE for WAN connection, switched to those setup after upgrading to 19.1.2.
So if I understand correct, IPS ist not supportef for WAN Interfaces with PPPoE?

Br
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: IPS stops working (19.1.2)
« Reply #3 on: March 05, 2019, 07:19:45 pm »
IPS on top of PPP in general, sorry. IDS works fine.


Cheers,
Franco
Logged

crt333

  • Jr. Member
  • **
  • Posts: 56
  • Karma: 0
    • View Profile
Re: IPS stops working (19.1.2)
« Reply #4 on: March 05, 2019, 08:41:06 pm »
I don't use PPP and ids/ips isn't recording alerts or generally working, even after upgrading to 19.1.2.

I used to see all kinds of alerts, now the only thing I've seen in the last month is "ET INFO Session Traversal Utilities for NAT (STUN Binding Request)". Even the ProofPoint summary window shows no events for days at a time.
Logged

Mks

  • Sr. Member
  • ****
  • Posts: 272
  • Karma: 19
    • View Profile
Re: IPS stops working (19.1.2)
« Reply #5 on: March 06, 2019, 10:50:31 am »
Ok, thanks
Logged

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: IPS stops working (19.1.2)
« Reply #6 on: June 21, 2019, 07:55:19 am »
Is this resolved? I still have flowbit-warnings and nearly no log-entries.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • IPS stops working (19.1.2)
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2