Latest Suricata bug fix is now available for download. Here is what the pfSense-pkg-suricata 3.0_2 package update addresses.
Bug Fixes
Rules auto-managed by SID MGMT tab files are not tagged correctly on the RULES tab.
IQRisk IP Reputation files not downloading for users with subscription code.
Icons indicating rule GID:SID added to Supress Lists get duplicated when IPs are the same on ALERTS tab.
Snort VRT rules checkboxes not auto-disabled when IPS-Policy is selected on CATEGORIES tab.
PCRE selection of SIDs not working correctly for auto-SID management.
Known Limitations:
At the moment, if you try select a Snort VRT IPS Policy and try to view all the rules selected by the policy on the RULES tab, you will crash the PHP process for the Suricata GUI and get a blank browser screen. This happens because the large IPS Policy rule set for the "Balanced" or "Security" policies exhausts the maximum PHP memory pool allowed by current pfSense settings. A solution for that is being looked into by the pfSense developers. In the interim, do not attempt to view an IPS Policy rule set on the RULES tab. Note that although doing so will crash the PHP process showing you the RULES tab page, it won't impact the firewall operation and will not crash the Suricata binary. It just crashes the individual process that was attempting to display the rules.
Bill