The other setup issue is using a bridged interface, which doesn't work for IPS because it requires real NIC driver to attach to.
We just need the following:A few variables of the affected devices and an anonymised "ifconfig" dump (the stack in this case: physical interface, vlan?, pppoe) and the expected and observed behaviour:Affected Versions: Suricata 3.1.1 on FreBSD 10.3expected: IPS (netmap) captures packets and generates alertsobserved: IPS I(netmap) does not capture any packetsNotes: IDS (pcap mode) can capture packets okI have a bug tracker account there so I could open the ticket a long as I can delay the questions the devs there have to you?Cheers,Franco
Hi Taomyn,You simply run this from SSH:# ifconfigRemove the public IP addresses (or send the dump to me via PM to anonymise it) and let us know how your WAN is set up (PPPoE - with or without VLAN, which physical interface, e.g. "em0").16.7.5 is Suricata 3.1.2, it would be good to know the behaviour is reproducible there too. Just let us know you're running/not running this version.Cheers,Franco