OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • No Internet access when IPS is on
« previous next »
  • Print
Pages: 1 [2]

Author Topic: No Internet access when IPS is on  (Read 8878 times)

GaardenZwerch

  • Full Member
  • ***
  • Posts: 104
  • Karma: 2
    • View Profile
Re: No Internet access when IPS is on
« Reply #15 on: October 16, 2019, 04:13:55 pm »
OK,
my tests (both Lab and Production) confirm this.
I run suricata on each VLAN and leave promiscuous mode on, and IPS works. I have tested with igb and ixl interfaces.

Thanks,
Frank
Logged

Cajuba

  • Newbie
  • *
  • Posts: 4
  • Karma: 1
    • View Profile
Re: No Internet access when IPS is on
« Reply #16 on: October 18, 2019, 11:30:41 am »
Meanwhile, I am a bit confused...  :-\

As I wrote in my previous posts I had to run IPS on my VLAN Interfaces, but not on the physical interface. Otherwise I would not get DHCP leases on my VLAN Subnets an I could not connect to the internet.

Then the world turned upside down...  :o
A few days ago I had to perform several reboots after some issues with power supply. After that I was not able to get a DHCP lease with the exact config that used to work before.  So I played around a bit.  After configuring IPS running on the physical LAN interface, but not on the VLAN interfaces anymore I immediately got DHCP Leases on all of my VLAN Subnets. This seems to be stable so far.

I have no idea why the system's behaviour changed after the reboots. From my point of view this seems to be quite strange...
Logged

Pocket_Sevens

  • Jr. Member
  • **
  • Posts: 73
  • Karma: 2
    • View Profile
Re: No Internet access when IPS is on
« Reply #17 on: October 18, 2019, 03:01:26 pm »
Quote from: GaardenZwerch on October 16, 2019, 04:13:55 pm
OK,
my tests (both Lab and Production) confirm this.
I run suricata on each VLAN and leave promiscuous mode on, and IPS works. I have tested with igb and ixl interfaces.

Thanks,
Frank

Hi Frank.

Thanks for testing this.  Just to clarify: was this on the VLANs only or also the physical LAN interface?
Logged

Pocket_Sevens

  • Jr. Member
  • **
  • Posts: 73
  • Karma: 2
    • View Profile
Re: No Internet access when IPS is on
« Reply #18 on: October 18, 2019, 03:03:51 pm »
Quote from: Cajuba on October 18, 2019, 11:30:41 am
Meanwhile, I am a bit confused...  :-\

As I wrote in my previous posts I had to run IPS on my VLAN Interfaces, but not on the physical interface. Otherwise I would not get DHCP leases on my VLAN Subnets an I could not connect to the internet.

Then the world turned upside down...  :o
A few days ago I had to perform several reboots after some issues with power supply. After that I was not able to get a DHCP lease with the exact config that used to work before.  So I played around a bit.  After configuring IPS running on the physical LAN interface, but not on the VLAN interfaces anymore I immediately got DHCP Leases on all of my VLAN Subnets. This seems to be stable so far.

I have no idea why the system's behaviour changed after the reboots. From my point of view this seems to be quite strange...

Hey Cajuba.  Did you upgrade to 19.7.5_5 per chance?
Logged

GaardenZwerch

  • Full Member
  • ***
  • Posts: 104
  • Karma: 2
    • View Profile
Re: No Internet access when IPS is on
« Reply #19 on: October 21, 2019, 03:29:21 pm »
Quote from: Pocket_Sevens on October 18, 2019, 03:01:26 pm
Quote from: GaardenZwerch on October 16, 2019, 04:13:55 pm
OK,
my tests (both Lab and Production) confirm this.
I run suricata on each VLAN and leave promiscuous mode on, and IPS works. I have tested with igb and ixl interfaces.

Thanks,
Frank

Hi Frank.

Thanks for testing this.  Just to clarify: was this on the VLANs only or also the physical LAN interface?


Hi,

IPS only on the VLANs, not on the physical NIC. Promiscuous mode ON.

Best regards,
Logged

Cajuba

  • Newbie
  • *
  • Posts: 4
  • Karma: 1
    • View Profile
Re: No Internet access when IPS is on
« Reply #20 on: October 21, 2019, 04:32:50 pm »
Quote from: Pocket_Sevens on October 18, 2019, 03:03:51 pm
Hey Cajuba.  Did you upgrade to 19.7.5_5 per chance?

Yes, my device is running on 19.7.5_5
Logged

  • Print
Pages: 1 [2]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • No Internet access when IPS is on
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2