OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Suricata 5 Beta - Can We Upload to OPNSense
« previous next »
  • Print
Pages: 1 [2]

Author Topic: Suricata 5 Beta - Can We Upload to OPNSense  (Read 9886 times)

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #15 on: June 26, 2019, 12:50:18 pm »
so i ask, if it makes sense to test s5 here?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #16 on: June 26, 2019, 01:27:19 pm »
Sure it makes sense, maybe it makes sense to switch logging to syslog and check eve.log about S5 findings.
Regarding the interface naming maybe it's worth to check release notes.

Most of the dev's are highly loaded with other tasks, that's why they'll start to test when S5 is stable (my personal view). Nonetheless, very appreciated when you start testing first!  8)
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #17 on: June 26, 2019, 01:44:11 pm »
OK, can we be sure, that the rulesets e.g. of ET Open are compatible between the versions?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #18 on: June 26, 2019, 02:59:11 pm »
I haven't tested them yet, but you should get some warnings in suricata log if they don't fit
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #19 on: June 27, 2019, 11:18:24 am »
Ok, it seems the logging is broken, but right now I have no idea if it's new logging features of 19.7 or Suricata itself.
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #20 on: August 26, 2019, 07:29:17 am »
i am quite sure, it's suricata itself, as i stepped down to 4.1. and still have problems with logging. I will now "upgrade" again to suricata 5 and continue testing.
Logged

ruggerio

  • Sr. Member
  • ****
  • Posts: 295
  • Karma: 11
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #21 on: August 26, 2019, 07:35:49 am »
btw. wouldn't it perhaps make sense, to plan suricata 5 for 20.1?
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #22 on: August 27, 2019, 06:07:33 pm »
It it's out and it works fine it's in 20.1, maybe even 19.7 later on. It depends on the release date. Probably some time this fall.


Cheers,
Franco
Logged

spetrillo

  • Hero Member
  • *****
  • Posts: 721
  • Karma: 8
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #23 on: October 20, 2019, 05:55:54 pm »
It looks like Suricata 5 is now a stable release. Is there a timetable for including it in OPNsense? Version 20 perhaps? Is there also a way to get other options added to the plugins, like Elastic Beats?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #24 on: October 20, 2019, 06:32:49 pm »
There is already a pkg for beats :)
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

spetrillo

  • Hero Member
  • *****
  • Posts: 721
  • Karma: 8
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #25 on: October 20, 2019, 06:48:31 pm »
Yes it is 6.7.1 but needs to be installed manually. Will it ever get added as a plug-in or will it always be manual?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #26 on: October 20, 2019, 10:48:38 pm »
I have a kind of enterprise plugin with a pure free field to configure, but it will never be merged.
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

spetrillo

  • Hero Member
  • *****
  • Posts: 721
  • Karma: 8
    • View Profile
Re: Suricata 5 Beta - Can We Upload to OPNSense
« Reply #27 on: October 20, 2019, 11:02:31 pm »
That is certainly too bad. I am trying to figure out how to keep Beats up to date on OPNsense. A bit of a pain.
Logged

  • Print
Pages: 1 [2]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Suricata 5 Beta - Can We Upload to OPNSense
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2