OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.1 Legacy Series »
  • Intrusion Detection, when enabled IPS not working
« previous next »
  • Print
Pages: 1 [2] 3

Author Topic: Intrusion Detection, when enabled IPS not working  (Read 10696 times)

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 9035
  • Karma: 618
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #15 on: October 14, 2016, 02:53:36 pm »
I got the PM. Did not create a ticket yet. Sorry for the delay.
Logged

Taomyn

  • Full Member
  • ***
  • Posts: 242
  • Karma: 11
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #16 on: October 14, 2016, 03:18:29 pm »
Quote from: franco on October 14, 2016, 02:53:36 pm
I got the PM. Did not create a ticket yet. Sorry for the delay.


No problem, I was more concerned that you didn't receive the information from me and was still waiting.
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 9035
  • Karma: 618
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #17 on: October 18, 2016, 11:23:15 pm »
The ticket was opened today: https://redmine.openinfosecfoundation.org/issues/1925
Logged

Taomyn

  • Full Member
  • ***
  • Posts: 242
  • Karma: 11
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #18 on: October 19, 2016, 08:58:11 am »
 8)  let me know if you/they require any more info from my setup.
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 9035
  • Karma: 618
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #19 on: October 19, 2016, 10:13:34 pm »
Will do. Right now, it's more of a technical discussion to locate the actual underlying issue.


Thanks,
Franco
Logged

Taomyn

  • Full Member
  • ***
  • Posts: 242
  • Karma: 11
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #20 on: November 03, 2016, 03:31:03 pm »
Anything happening about this?
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 9035
  • Karma: 618
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #21 on: November 07, 2016, 07:41:08 am »
Progress was slow: we exchanged a few emails and another user here provided trace files on top of the non-working config. We don't have an outlook just yet.
Logged

Taomyn

  • Full Member
  • ***
  • Posts: 242
  • Karma: 11
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #22 on: December 04, 2016, 09:17:16 am »
Any news?
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 9035
  • Karma: 618
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #23 on: December 05, 2016, 05:24:52 pm »
We did talk about it with Victor from Suricata and he said the PPPoE doesn't look different, but for some reason the traffic is not properly processed. We're missing some bit of intel (or a reproducible setup) without which we cannot continue to uncover the underlying issue.
Logged

Taomyn

  • Full Member
  • ***
  • Posts: 242
  • Karma: 11
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #24 on: December 05, 2016, 06:33:27 pm »
Quote from: franco on December 05, 2016, 05:24:52 pm
We did talk about it with Victor from Suricata and he said the PPPoE doesn't look different, but for some reason the traffic is not properly processed. We're missing some bit of intel (or a reproducible setup) without which we cannot continue to uncover the underlying issue.

So what can I provide you from my setup to hopefully give you what is missing? I'll happily install/config things to get more diagnostics if that would help.
Logged

Taomyn

  • Full Member
  • ***
  • Posts: 242
  • Karma: 11
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #25 on: March 14, 2017, 09:55:57 am »
Now that v17 has been out a while, any chance of re-visiting this issue?


Also, can this thread be moved to the v17 sub-forum seeing as it applies to it as well?
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 9035
  • Karma: 618
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #26 on: March 14, 2017, 02:10:47 pm »
Moved as requested. A netmap bug with Suricata / FreeBSD 12-CURRENT and another IPsec have priority at the moment.
Logged

elektroinside

  • Hero Member
  • *****
  • Posts: 574
  • Karma: 50
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #27 on: January 09, 2018, 12:10:24 am »
Hi guys,

Same issue here, no IDS/IPS on PPPoE.
Is there something I can help with?

I'm on base/kernel 18.1.b, everything up to date.
OPNsense 17.7.11-amd64
FreeBSD 11.1-RELEASE-p2
LibreSSL 2.5.5

Just switched from pfsense a few days ago. Everything looks so much nicer here, the code, the quality, the community, the support. I'm happy I switched. Thank you for all your hard work!
Logged
OPNsense v18 | HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s

Team Rebellion Member

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 9035
  • Karma: 618
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #28 on: January 09, 2018, 08:56:04 am »
Hi there,

This issue is still beyond our reach. Suricata now considers Netmap and FreeBSD a first level support tier, although that won't help us if the FreeBSD kernel side is not up to the task, which is the case here.

For the most part it's recommended to run Suricata on the internal networks, not the PPPoE WAN interfaces where this issue does not apply as well. It may require tweaking the HOME_NET setting under the advanced options.


Cheers,
Franco
Logged

elektroinside

  • Hero Member
  • *****
  • Posts: 574
  • Karma: 50
    • View Profile
Re: Intrusion Detection, when enabled IPS not working
« Reply #29 on: January 09, 2018, 09:45:28 am »
Indeed. Well, things are looking good anyway on the LAN side, for now, without any tweakings as per this setup. Hopefully, the kernel will be updated soon or workarounds implemented for this to work properly.

Thanks Franco!
Logged
OPNsense v18 | HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s

Team Rebellion Member

  • Print
Pages: 1 [2] 3
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.1 Legacy Series »
  • Intrusion Detection, when enabled IPS not working
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2019 All rights reserved
  • SMF 2.0.15 | SMF © 2017, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2