Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
Suricata 5 Beta - Can We Upload to OPNSense
« previous
next »
Print
Pages: [
1
]
2
Author
Topic: Suricata 5 Beta - Can We Upload to OPNSense (Read 9857 times)
spetrillo
Hero Member
Posts: 721
Karma: 8
Suricata 5 Beta - Can We Upload to OPNSense
«
on:
June 01, 2019, 03:19:22 am »
Hello all,
Is there an ability to upload a new package, in this case the Suricata 5 beta, so it can be installed via GUI. Does this need to be done via CLI instead?
Thanks,
Steve
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #1 on:
June 03, 2019, 05:06:37 pm »
Hi Steve,
Working on this for 19.1.9 although we won't have suricata-devel package installable with a single click at the moment as the core package will need to be rebuilt from the git repository with the suricata package replaced.
Cheers,
Franco
Logged
spetrillo
Hero Member
Posts: 721
Karma: 8
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #2 on:
June 03, 2019, 05:23:22 pm »
No worries...and thanks for all the efforts. I am learning alot about OPNsense!
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #3 on:
June 03, 2019, 05:37:04 pm »
Ping me after 19.1.9 is out to post instructions here on how to use Suricata 5 package. I have to give it a good testing beforehand to make sure nothing unpleasant happens.
Cheers,
Franco
Logged
ruggerio
Sr. Member
Posts: 295
Karma: 11
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #4 on:
June 04, 2019, 07:59:51 am »
as i will be soon happy owner of a apu4, i will join the testing then.
Logged
spetrillo
Hero Member
Posts: 721
Karma: 8
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #5 on:
June 12, 2019, 04:20:31 am »
Hey @franco is it time to test the Suricata 5 install?
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #6 on:
June 12, 2019, 06:45:16 am »
When on 19.1.9:
pkg install suricata-devel
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
ruggerio
Sr. Member
Posts: 295
Karma: 11
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #7 on:
June 12, 2019, 07:56:48 am »
this will try to uninstall pkg opnsense-19.1.9
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #8 on:
June 12, 2019, 01:15:30 pm »
Switch to development and do an upgrade to install it. Then on the console:
# opnsense-code core
# cd /usr/core
# make upgrade CORE_SURICATA=-devel
Cheers,
Franco
Logged
ruggerio
Sr. Member
Posts: 295
Karma: 11
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #9 on:
June 12, 2019, 08:19:59 pm »
thx! on s5 now. just done some testing with eicar, this works quite well.
i had another firewall with ipfire/suricata in parallel - what is astaunishing, this one drops attacks like crazy with the same rule (compromised i think are good for testing) - whilst i nearly see no attack on opnsense.
Logged
ruggerio
Sr. Member
Posts: 295
Karma: 11
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #10 on:
June 17, 2019, 07:28:50 am »
After a few days, i cannot see any difference between 5 beta and 4. Should there be a difference?
All what i've seen so far, CPU is no longer on high load for long time, if downloading e.g. a 2 GB DVD-ISO.
Logged
ruggerio
Sr. Member
Posts: 295
Karma: 11
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #11 on:
June 18, 2019, 03:48:29 pm »
After changing some rules today i have the following message:
suricata: [100705] <Warning> -- [ERRCODE: SC_WARN_OPTION_OBSOLETE(233)] - netmap interface igb2+ uses obsolete '+' notation. Using '^' instead
in this case, its the wan-interface. But this comes for all interfaces.
And: get nearly no entries in Alert-log, but having a web- and mailserver with both imap and smtp-rules...). This feels a little bit strange. On Suricata 4 too.
Logged
ruggerio
Sr. Member
Posts: 295
Karma: 11
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #12 on:
June 21, 2019, 07:19:39 am »
still only entries in alarm-tab, if i test a eicar. Nothing else. I am not sure, if it is working correct. Somebody else perhaps with more reliable results?
btw. i am in IPS-Mode. Will switch now to IDP.
«
Last Edit: June 21, 2019, 08:00:10 am by ruggerio
»
Logged
ruggerio
Sr. Member
Posts: 295
Karma: 11
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #13 on:
June 26, 2019, 07:52:01 am »
Still no change - am i the only tester for the moment? When is 5 planned in opnsense for golive?
btw. i deleted all the rules in /usr/local/etc/suricata/rules and ./opnsense-rules, as i got massy of errors of flowbits set. Re-downloaded all the rules i checked, but the errors persist.
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Suricata 5 Beta - Can We Upload to OPNSense
«
Reply #14 on:
June 26, 2019, 11:24:33 am »
S5 isn't stable yet, so there are no plans to migrate.
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Print
Pages: [
1
]
2
« previous
next »
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
Suricata 5 Beta - Can We Upload to OPNSense