OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Error with IPS activation
« previous next »
  • Print
Pages: [1]

Author Topic: Error with IPS activation  (Read 1243 times)

klaxzygen

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Error with IPS activation
« on: August 27, 2024, 12:54:46 am »
Hello community,

I run opnsense [24.7.2] on Protectli Vault Pro VP2420 + zenarmor and have a very strange issue when I activate suricata IPS. Once activated it runs for a few seconds and then service crashes with the error below. IDS works fine, this happens only when I activate IPS mode.

Code: [Select]
Error suricata [104135] <Error> -- opening devname netmap:igc1-0/R@conf:host-rings=4 failed: Device busy
What I did so far to troubleshoot was to disable all hardware offloading incl. CRC, TSO & LRO but that only broke the connectivity and access to UI and internet was gone.

The interfaces I want to active IPS on are VLAN interfaces and physical WAN interface.

Any help with getting this work is appreciated!

Thanks,
N
Logged

doktornotor

  • Hero Member
  • *****
  • Posts: 709
  • Karma: 70
    • View Profile
Re: Error with IPS activation
« Reply #1 on: August 28, 2024, 11:39:55 am »
With any HW offloading, it will NOT work. Deactivating that properly requires a reboot.
Logged

klaxzygen

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: Error with IPS activation
« Reply #2 on: August 28, 2024, 07:24:59 pm »
Deactivating HW offload and rebooting breaks the connectivity to internet and UI. I needed to login physically to firewall and stop the suricata service in order to access the UI again.
Logged

doktornotor

  • Hero Member
  • *****
  • Posts: 709
  • Karma: 70
    • View Profile
Re: Error with IPS activation
« Reply #3 on: August 28, 2024, 08:19:02 pm »
Uhm, no, it does not break any internet., You cannot use IPS with HW accelleration for reasons mentioned in the documentation (the netmap driver you can see in the error message you posted) - and that is the end of the story.
Logged

MarieSophieSG

  • Full Member
  • ***
  • Posts: 172
  • Karma: 5
  • Your avrge girl playing wi/ computers and engineri
    • View Profile
Re: Error with IPS activation
« Reply #4 on: September 21, 2024, 09:18:34 pm »
Quote from: klaxzygen on August 28, 2024, 07:24:59 pm
Deactivating HW offload and rebooting breaks the connectivity to internet and UI. I needed to login physically to firewall and stop the suricata service in order to access the UI again.

My 2cts (of a newbe going through the same problems for the past few days)
Seems that you have two problems, but you should be working on just one:

- Since you can't have HW offloading (CRC, TSO & LRO) and IPS (and even IDS on some mat'l) you have no choice but to keep them checked (disabled)
=> You should first work on that part, why is it breaking your connection ?

- Then start IDS, then start IPS
Logged
Hunsn RS39 (N5105, 4x i225) 24.7.5_0 testing
LAN1 = swtch1 Laptop1 MX23, NAS, Laptop2 Win10
LAN2 = WiFi router AP, Laptop2, tablet, phone, printer, IoT, etc.
LAN3 = Swtch2 Laptop3 Suse; Laptop4 Qube-OS/Win10, printer
Pretending to be tech Savvy with a HomeLab :-p

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Error with IPS activation
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2