Also having random issues with routing to WAN interface. Restarting all services using SSH console restores routing. Issue solved after disabling IDS/IPS and Suricata. Only disabling Suricata did not solve the issue. IDS/IPS was active on WAN and Suricata was active on all LAN/VLANs.
It seems the actual issue is that non-physical interfaces are enabled in Suricata IPS mode where the new libnetmap/Suricata combination will move these previously defunct setups (IPS doesn't work but traffic goes through) from defunct setup (IPS will be enabled on these interfaces in emulation mode causing traffic drops eventually due to partial support).We will revert the behaviour for 21.7.x, but in 22.1 and up we would ask users to take more care in verifying their setups beforehand.None of this was ever an issue on using IPS mode for physical interfaces or VLAN parents in promiscuous mode when VLAN scanning is necessary.Cheers,Franco
2021-12-15T10:39:36 suricata[60953] [100520] <Notice> -- all 4 packet processing threads, 4 management threads initialized, engine started. 2021-12-15T10:39:34 suricata[58549] [100680] <Notice> -- This is Suricata version 6.0.4 RELEASE running in SYSTEM mode 2021-12-15T10:39:33 suricata[36929] [100447] <Notice> -- Signal Received. Stopping engine. 2021-12-15T03:18:01 suricata[36929] [100447] <Notice> -- rule reload complete 2021-12-15T03:18:01 suricata[36929] [100447] <Notice> -- rule reload starting 2021-12-14T23:24:18 suricata[36929] [100447] <Notice> -- all 4 packet processing threads, 4 management threads initialized, engine started. 2021-12-14T23:24:16 suricata[27169] [100448] <Notice> -- This is Suricata version 6.0.4 RELEASE running in SYSTEM mode 2021-12-14T23:24:15 suricata[88364] [100551] <Notice> -- Signal Received. Stopping engine.
2021-12-15T11:28:24 suricata[29857] [100447] <Notice> -- all 4 packet processing threads, 4 management threads initialized, engine started. 2021-12-15T11:28:24 suricata[29857] [100888] <Notice> -- opened netmap:igb2/T from igb2: 0x8c35aa2300 2021-12-15T11:28:24 suricata[29857] [100888] <Notice> -- opened netmap:igb2^ from igb2^: 0x8c35aa2000 2021-12-15T11:28:23 suricata[29857] [100879] <Notice> -- opened netmap:igb2^ from igb2^: 0x8c0b5f7300 2021-12-15T11:28:23 suricata[29857] [100879] <Notice> -- opened netmap:igb2/R from igb2: 0x8c0b5f7000 2021-12-15T11:28:23 suricata[29857] [100878] <Notice> -- opened netmap:igb1/T from igb1: 0x8bcbdfd300 2021-12-15T11:28:23 suricata[29857] [100878] <Notice> -- opened netmap:igb1^ from igb1^: 0x8bcbdfd000 2021-12-15T11:28:22 suricata[29857] [100869] <Notice> -- opened netmap:igb1^ from igb1^: 0x8bb6ca3300 2021-12-15T11:28:22 suricata[29857] [100869] <Notice> -- opened netmap:igb1/R from igb1: 0x8bb6ca3000 2021-12-15T11:28:22 suricata[25946] [100432] <Notice> -- This is Suricata version 6.0.4 RELEASE running in SYSTEM mode 2021-12-15T11:28:21 suricata[92259] [100589] <Notice> -- Stats for 'igb1^': pkts: 51783, drop: 0 (0.00%), invalid chksum: 0 2021-12-15T11:28:21 suricata[92259] [100589] <Notice> -- Stats for 'igb1': pkts: 12554, drop: 0 (0.00%), invalid chksum: 0 2021-12-15T11:28:21 suricata[92259] [100589] <Notice> -- Signal Received. Stopping engine.