Suricata IDS dropping outbound traffic

Started by marcusdevane, October 07, 2026, 03:41:39 PM

Previous topic - Next topic
Hi everyone, I recently deployed OPNsense on my home network with Suricata enabled on the LAN interface, and I have run into an issue with unexpected connection resets. A user on my local subnet has been running deltaexeutor on a client machine, but the client repeatedly fails to establish a stable handshake with external endpoints and times out during startup requests.

Looking through the live firewall logs, I see outbound sessions destined getting prematurely terminated or intermittently rejected by rule matching. What would be the best practice in OPNsense to verify whether this is an IDS false positive or an aggressive state timeout, without having to create an overly broad bypass rule for that entire machine?