Suricatas "INDICATOR-SHELLCODE x86 setgid 0" Killing my VPN connection
-
Hay guys, so after a long time trying to work out why my VPN was dying whenever it was loaded up:
https://forum.netgate.com/topic/188436/potential-issues-with-hardware
I have found these to be blocking the VPNs IP:
"INDICATOR-SHELLCODE x86 setgid 0" and "INDICATOR-SHELLCODE x86 setuid 0"Would it be safe to just kill that rule. I don't really want to but it is on my WAN side and all my network goes through the VPN, so don't think its too bad is it?
-
@unique_username Presumably you enabled those rules for a reason…?
I would just say, try moving Suricata to LAN which will also avoid scanning all the packets that would normally be dropped by the firewall.
Also if it’s just one IP being blocked you can suppress that alert for that IP.