OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 20.7 Legacy Series »
  • Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
« previous next »
  • Print
Pages: [1]

Author Topic: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.  (Read 3322 times)

Archanfel80

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 6
    • View Profile
Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
« on: August 06, 2020, 03:35:22 pm »
After upgrade from the latest 20.1.x to the 20.7 the firewall crashed right after the suricata service loaded. Some sort of CPU error, i cant see its scrolling too fast, then immediately reboot the machine. This stuck into a loop.
Full clean 20.7 install then restore the config.xml also cause this issue.
So the problem is with the suricata related part in the config.xml. Or even the whole suricata module bugged.
Make sure you are disabled before the upgrade.
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
« Reply #1 on: August 06, 2020, 04:27:13 pm »
It's related to netmap. See this thread:

https://forum.opnsense.org/index.php?topic=17363.msg83997#msg83997

Logged

EHRETic

  • Newbie
  • *
  • Posts: 42
  • Karma: 0
    • View Profile
Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
« Reply #2 on: August 07, 2020, 08:56:48 am »
Same for me (it's a VM, no VLAN tagging, interface firectly on Internet with public address)

I let the IPS without blocking mode for now. At the second you activate blocking mode, it crashs ;D
Logged

Archanfel80

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 6
    • View Profile
Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
« Reply #3 on: August 07, 2020, 09:10:54 am »
Yes! Its a vmware VM on my side too, no vlan just native interfaces. As soon as i enabled blocking, the OS crashed and reset, then its stuck in a loop. Its an urgent issue since we use IPS many FW. Im reverted to 20.1 for now.

Quote from: EHRETic on August 07, 2020, 08:56:48 am
Same for me (it's a VM, no VLAN tagging, interface firectly on Internet with public address)

I let the IPS without blocking mode for now. At the second you activate blocking mode, it crashs ;D
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
« Reply #4 on: August 07, 2020, 06:10:58 pm »
A test kernel for 20.7 should be out soon. Till then, it's safe to stay on 20.1.
Logged

W0nderW0lf

  • Full Member
  • ***
  • Posts: 167
  • Karma: 2
    • View Profile
Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
« Reply #5 on: August 07, 2020, 06:27:00 pm »
I agree with mb.
Tried out 20.1 again and after restoring from backup, everything worked as before.
I also noticed, while looking at the opnsense terminal. Every Browser action on the dashboard, gets instantly stdout to the terminal. This never happened before. Hope we wont have to wait 2 long for a fix. :)

By the way, this bug seems to not only affect VM's since I am running Opnsense on bare metal with Intel chips.
« Last Edit: August 07, 2020, 06:28:34 pm by W0nderW0lf »
Logged

Archanfel80

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 6
    • View Profile
Re: Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
« Reply #6 on: August 07, 2020, 07:54:56 pm »
If i understand correctly this is not the opnsense issue but the freebsd and the kernel.
This "hardened" BSD project is a way to overkill for everyday use. Its cause trouble trouble trouble.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 20.7 Legacy Series »
  • Upgrade from 20.1 -> 20.7 failed when IPS/IDS enabled.
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2