Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Important Snort and Suricata Package Announcement -- probable bug in Legacy Blocking Module

    Scheduled Pinned Locked Moved IDS/IPS
    82 Posts 15 Posters 17.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      InstanceExtension @bmeeks
      last edited by

      @bmeeks Add me to the list of 2.7.0 CE (just downgraded from Plus on Oct 31st) using Snort legacy mode and seeing core dumps. Mine all seems to occur just after a rules update when Snort is restarted, Does not occur with each rules update and restart though. Has occurred 3 times since Nov 1st.

      1 Reply Last reply Reply Quote 0
      • Bob.DigB
        Bob.Dig LAYER 8 @bmeeks
        last edited by Bob.Dig

        @bmeeks said in Important Snort and Suricata Package Announcement -- probable bug in Legacy Blocking Module:

        Give it some running time. The fault is not always instantaneous for other users. Some are seeing up to 30 minutes of runtime before a fault.

        Still nothing to report here for Suricata.


        Capture.PNG

        NogBadTheBadN 1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad @Bob.Dig
          last edited by

          @Bob-Dig You're running In-line mode aren't you ?

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          Bob.DigB 1 Reply Last reply Reply Quote 0
          • Bob.DigB
            Bob.Dig LAYER 8 @NogBadTheBad
            last edited by

            @NogBadTheBad No, legacy.

            1 Reply Last reply Reply Quote 1
            • bmeeksB bmeeks referenced this topic on
            • bmeeksB
              bmeeks
              last edited by

              Update -- I was finally able to experience the Signal 11 core dump on my CE 2.7.0-RELEASE testing machine. It took about an hour for the event to trigger. Seemed to happen when it attempted to kill open states.

              I am now building a debug-enabled version of Snort for further testing to see if I can trigger the fault again. Having a debug-enabled version will help track down what's happening. Since the fault happens randomly, this may take a bit to work out.

              Bob.DigB 1 Reply Last reply Reply Quote 4
              • Bob.DigB
                Bob.Dig LAYER 8 @bmeeks
                last edited by Bob.Dig

                @bmeeks Just another Datapoint regarding Suricata. I let it run over two hours on my VPS with pfSense CE RC on WAN. Hundreds of blocks, still no problem.

                bmeeksB 1 Reply Last reply Reply Quote 0
                • bmeeksB
                  bmeeks @Bob.Dig
                  last edited by

                  @Bob-Dig said in Important Snort and Suricata Package Announcement -- probable bug in Legacy Blocking Module:

                  @bmeeks Just another Datapoint regarding Suricata. I let it run over two hours on my VPS with pfSense CE RC on WAN. Hundreds of blocks, still no problem.

                  Is this with Kill States checked or unchecked on the INTERFACE SETTINGS tab?

                  Bob.DigB 1 Reply Last reply Reply Quote 0
                  • Bob.DigB
                    Bob.Dig LAYER 8 @bmeeks
                    last edited by Bob.Dig

                    @bmeeks Checked. The only thing of note, I block only for 15 mins, so right now there are "only" 33 blocks and no snort-rules.
                    suricata 7.0.2

                    Cool_CoronaC Bob.DigB 2 Replies Last reply Reply Quote 1
                    • Cool_CoronaC
                      Cool_Corona @Bob.Dig
                      last edited by

                      @Bob-Dig Run it "infinete" and you will see :)

                      1 Reply Last reply Reply Quote 0
                      • Bob.DigB
                        Bob.Dig LAYER 8 @Bob.Dig
                        last edited by Bob.Dig

                        @Bob-Dig said in Important Snort and Suricata Package Announcement -- probable bug in Legacy Blocking Module:

                        I block only for 15 mins, so right now there are "only" 33 blocks and no snort-rules.
                        suricata 7.0.2

                        Run it over night, still no problem, will stop it now.

                        fireodoF 1 Reply Last reply Reply Quote 0
                        • fireodoF
                          fireodo @Bob.Dig
                          last edited by

                          @Bob-Dig said in Important Snort and Suricata Package Announcement -- probable bug in Legacy Blocking Module:

                          Run it over night, still no problem, will stop it now.

                          Probably, in your case, the second condition (kill states is the main one) is not occurring (considering Bill Meeks theory) so there is no crash ... 🤔

                          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                          pfsense 2.8.0 CE
                          Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                          Bob.DigB 1 Reply Last reply Reply Quote 0
                          • Bob.DigB
                            Bob.Dig LAYER 8 @fireodo
                            last edited by

                            @fireodo My theory is, it is a snort problem, not suricata. Let's see.

                            fireodoF 1 Reply Last reply Reply Quote 0
                            • fireodoF
                              fireodo @Bob.Dig
                              last edited by

                              @Bob-Dig said in Important Snort and Suricata Package Announcement -- probable bug in Legacy Blocking Module:

                              @fireodo My theory is, it is a snort problem, not suricata. Let's see.

                              👍

                              Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                              SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                              pfsense 2.8.0 CE
                              Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                              G 1 Reply Last reply Reply Quote 0
                              • S
                                slu @bmeeks
                                last edited by

                                @bmeeks

                                don't see such an issue on my two 2.7.0 CE boxes:
                                2.7.0 CE
                                Snort 4.1.6_13
                                Legacy Mode
                                Kill States enabled

                                pfSense Gold subscription

                                1 Reply Last reply Reply Quote 0
                                • G
                                  Gblenn @fireodo
                                  last edited by Gblenn

                                  I have Suricata running in Legacy mode at two different sites, (2.7.0 and 23.09). Both with Kill States enabled and no problems whatsoever...

                                  Bob.DigB 1 Reply Last reply Reply Quote 0
                                  • Bob.DigB
                                    Bob.Dig LAYER 8 @Gblenn
                                    last edited by

                                    @slu Do you have actually blocks?

                                    G S 3 Replies Last reply Reply Quote 0
                                    • G
                                      Gblenn @Bob.Dig
                                      last edited by Gblenn

                                      @Bob-Dig Yes I do, and I have the Remove Blocked Hosts Interval set to 1h but could change it to something higher if that would have an effect?
                                      Up until a few days ago I have had the 23.09 site set up with Block on DROP Only NOT being checked. Meaning I had every single Alert resulting in a Block and basically having built up a Passlist that works for me. As a result I would usually see quite a long list in the Blocks tab. Most of them ET INFO actually, but still blocks.
                                      The 2.7.0 site is also set up this way, but it's for our vacation home so not much going on there at the moment.

                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        slu @Bob.Dig
                                        last edited by

                                        @Bob-Dig
                                        good point, no, not at the moment.

                                        pfSense Gold subscription

                                        G 1 Reply Last reply Reply Quote 0
                                        • G
                                          Gblenn @slu
                                          last edited by

                                          @slu said in Important Snort and Suricata Package Announcement -- probable bug in Legacy Blocking Module:

                                          @Bob-Dig
                                          good point, no, not at the moment.

                                          😊 Ah, that was a question to you obviously...

                                          1 Reply Last reply Reply Quote 0
                                          • S
                                            slu @Bob.Dig
                                            last edited by

                                            @Bob-Dig said in Important Snort and Suricata Package Announcement -- probable bug in Legacy Blocking Module:

                                            @slu Do you have actually blocks?

                                            You are right, searching in the logs and found it:

                                            Nov 15 06:47:55 	kernel 		pid 44159 (snort), jid 0, uid 0: exited on signal 11 (core dumped)
                                            

                                            pfSense Gold subscription

                                            Bob.DigB 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.