2.7.2: altq (HFSC) + Suricata (inline)
-
All,
Are ALTQ (HFSC) and Suricata [inline] fundamentally incompatible? Trying to determine if this is a defect or expected?
Behavior: If an interface has Suricata running (inline), packets never pass through any queue on that interface. On one hand it makes sense that they would not be, but on the other hand seems like both should be viable.
Spent some hours attempting to configure, re-config, test, (wash rinse repeat for hours) and could not get any packets to pass through a queue. It wasn't until queueing was applied to all interfaces that it was realized - packets would only pass through queues on interfaces that didn't have Suricata running on the interface.
Thanks!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.