Enable IPS prevents DHCP on VLANs

Started by grimm26, August 26, 2021, 05:10:56 PM

Previous topic - Next topic
August 26, 2021, 05:10:56 PM Last Edit: August 27, 2021, 04:48:36 AM by grimm26
I'm running 21.7.1

I've been using suricata for a couple years. Originally, I had no VLANs and ran a pretty flat network. I recently redid my network and added an AP that supports VLANs. It it connected to its own interface on my router PC, my wired switch connects to another interface. I am running several VLANs on the WLAN. I realized yesterday that I never enabled suricata on the network port (igb) that the AP is on, so I did that yesterday.  Everything on a Wifi VLAN broke.
Details I have since found:

  • Things are only broken if IPS is enabled
  • Things are still broken even with no rules with IPS enabled
  • clients are not able to get a DHCP address assigned.

As I was writing this I realize that it looks like dhcpd is trying to assign clients on the VLANs an address for the physical subnet for that port and then the client can't use that IP because it is for the wrong network.

Is there some settings I need to tweak somewhere?

Had the same issue. It can be resolved as follows:
- disable VLAN hardware filtering. REBOOT (!!).
- enable IDS, enable promiscuous mode and only apply IDS on physical interfaces.

Then it works.

Can't stress the "REBOOT" bit enough.

Yes! The disabling VLAN hardware filtering is what I was missing. I had it set to default. Thank you.