OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.1 Legacy Series »
  • [SOLVED] Intrusion Detection (suricata) keeps exiting
« previous next »
  • Print
Pages: 1 [2]

Author Topic: [SOLVED] Intrusion Detection (suricata) keeps exiting  (Read 10630 times)

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13929
  • Karma: 1208
    • View Profile
Re: [SOLVED] Intrusion Detection (suricata) keeps exiting
« Reply #15 on: February 27, 2017, 05:30:51 pm »
Odd. What's the output of:

# uname -a


Cheers,
Franco
Logged

pbolduc

  • Newbie
  • *
  • Posts: 42
  • Karma: 4
    • View Profile
Re: [SOLVED] Intrusion Detection (suricata) keeps exiting
« Reply #16 on: February 27, 2017, 05:43:38 pm »
It Reads:

FreeBSD OPNSense.localdomain 11.0-RELEASE-p7 FreeBSD 11.0-RELEASE-p7 #0 ca29eed2d(Stable/17.1): Mon Feb 20 15:24:20 CET 2017 root@sensey32:/usr/obj/usr/src/sys/SMP i386
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13929
  • Karma: 1208
    • View Profile
Re: [SOLVED] Intrusion Detection (suricata) keeps exiting
« Reply #17 on: February 27, 2017, 05:49:30 pm »
Ok, so far so good.

Can you post output of the following command before an after reinstalling the kernel?

# ls -lah /dev/netmap

The kernel reinstalls with:

# opnsense-update -fk
# /usr/local/etc/rc.reboot

And then try again. So far it looks like Suricata can't start because you set IPS mode but the kernel module for IPS is gone which is rather odd.

Also, what network cards / drivers are you using?


Cheers,
Franco
Logged

pbolduc

  • Newbie
  • *
  • Posts: 42
  • Karma: 4
    • View Profile
Re: [SOLVED] Intrusion Detection (suricata) keeps exiting
« Reply #18 on: February 27, 2017, 06:00:25 pm »
I am unable to proceed as the device is in use at the moment. I will try and perform these steps at the end of day. Thank you for your time. The network drivers would be the Intel E1000.

When I run before the reboot:  "ls -lah /dev/netmap" it returns  "ls: /dev/netmap: No such file or directory"

I was able to get Suricata to start by disabling IPS.
« Last Edit: February 27, 2017, 06:47:58 pm by pbolduc »
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13929
  • Karma: 1208
    • View Profile
Re: [SOLVED] Intrusion Detection (suricata) keeps exiting
« Reply #19 on: February 27, 2017, 10:51:23 pm »
Ok, netmap was missing from i386 since 17.1, which affected IPS mode only. FreeBSD added netmap to their 11.0 config, but only for amd64, not i386. Sorry about this.

The kernel is fixed and syncing to the mirrors. Just reapply 17.1.2:

# opnsense-update -fk
# /usr/local/etc/rc.reboot

And it should be all good when the /dev/netmap device is back.


Cheers,
Franco
Logged

pbolduc

  • Newbie
  • *
  • Posts: 42
  • Karma: 4
    • View Profile
Re: [SOLVED] Intrusion Detection (suricata) keeps exiting
« Reply #20 on: February 28, 2017, 01:38:46 am »
Yep, that fixed it after reapplying 17.1.2. Thanks very much!
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13929
  • Karma: 1208
    • View Profile
Re: [SOLVED] Intrusion Detection (suricata) keeps exiting
« Reply #21 on: March 02, 2017, 08:12:04 am »
Ok, change will become permanent in 17.1.3.


Cheers,
Franco
Logged

  • Print
Pages: 1 [2]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.1 Legacy Series »
  • [SOLVED] Intrusion Detection (suricata) keeps exiting
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2