Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata on Pfsense

    Scheduled Pinned Locked Moved IDS/IPS
    30 Posts 8 Posters 11.3k Views 10 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      SteveITS Galactic Empire @bmeeks
      last edited by

      @bmeeks :( well thank you for your time, sir. 🫡

      Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
      Upvote 👍 helpful posts!

      1 Reply Last reply Reply Quote 0
      • N Offline
        NRgia @bmeeks
        last edited by

        @bmeeks Thank you for what you did for Snort or Suricata. I'm not sure what you want me to do on Redmine, due to is a bug tracker.

        My question is for Product Management, which I will ask it here to be public: What is the plan for these 2 packages, Suricata and Snort?

        Thank you

        bmeeksB B 2 Replies Last reply Reply Quote 0
        • bmeeksB Offline
          bmeeks @NRgia
          last edited by bmeeks

          @NRgia said in Suricata on Pfsense:

          @bmeeks Thank you for what you did for Snort or Suricata. I'm not sure what you want me to do on Redmine, due to is a bug tracker.

          My question is for Product Management, which I will ask it here to be public: What is the plan for these 2 packages, Suricata and Snort?

          Thank you

          Yes, Redmine is for both bug reports and feature requests. Asking for the Suricata binary to be updated to the latest 7.0.11 version from upstream is a legitimate Redmine request. I would suggest simply asking for the binary version update instead of asking about future Netgate strategy (such as the support plans for the packages). Strategy discussions typically don't get very far because they deal with proprietary information or plans that a company may not want to publicly discuss.

          Redmine is where the Netgate developer team tracks all the code changes they make for pfSense. They will see Redmine reports much quicker than a forum post.

          1 Reply Last reply Reply Quote 0
          • B Offline
            btspce @NRgia
            last edited by

            @NRgia I have created an redmine request now as the binary was not updated in the recent update and there was no answer from netgate here in all this time.

            N tinfoilmattT 2 Replies Last reply Reply Quote 1
            • N Offline
              NRgia @btspce
              last edited by

              @btspce Thank you. Do you know if this will be the process to follow moving forward? Normal users are required to open tickets in order to get updates? Or is there a point of contact that we can nudge for this cases.

              S 1 Reply Last reply Reply Quote 0
              • S Offline
                SteveITS Galactic Empire @NRgia
                last edited by

                @NRgia

                Redmine is where the Netgate developer team tracks all the code changes they make for pfSense

                Redmine is a bug/feature tracker.

                Generally newer versions of pfSense have newer versions of various software (FreeBSD packages) that are included in the base install.

                pfSense packages like Snort/Suricata or other "not included by default" software are maintained separately and may or may not get updated when pfSense is updated, and sometimes are updated in between.

                If you have a redmine.pfsense.org account there is a Watch link at the top right of each request/issue, next to Edit.

                It's unclear from above who is maintaining the Suricata package now.

                Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                Upvote 👍 helpful posts!

                bmeeksB N 2 Replies Last reply Reply Quote 1
                • bmeeksB Offline
                  bmeeks @SteveITS
                  last edited by bmeeks

                  @SteveITS said in Suricata on Pfsense:

                  It's unclear from above who is maintaining the Suricata package now.

                  The package no longer has any active maintainer. The Netgate team did decide to address a couple of recent PHP GUI package CVEs themselves (that's the recent update to 7.0.8_3, I believe). I would not expect Netgate to takeover continuous maintenance of the package as it is not a core package of pfSense.

                  Best case is for another community member to step up and take over package maintenance.

                  P.S. -- I did send a detailed email a couple of weeks ago to the pfSense developer team letting them know of my retirement from package maintainer duties. They acknowledged receipt of the notice, so they are aware of the current package status (ditto for the Snort package, too).

                  fireodoF 1 Reply Last reply Reply Quote 3
                  • N Offline
                    NRgia @SteveITS
                    last edited by

                    @SteveITS I understand, but let's speak from the user/client point of view. Why a client must raise tickets in a bugtracker like Redmine or Jira or whatever? A client expectation is that, if a package is available, to be updated or maintained.

                    If the package is not maintained it will become a security and performance issue with time.

                    I mean I understand, maybe, Netgate doesn't have resources, but then, they can remove it, instead of waiting for something to happen...

                    Just my 2 cents.

                    @bmeeks Your suggestion is preferred, but from I understood from you, nobody is interested or have the knowledge.
                    Again thank you, for updating this package over the years.

                    bmeeksB 1 Reply Last reply Reply Quote 0
                    • bmeeksB Offline
                      bmeeks @NRgia
                      last edited by bmeeks

                      @NRgia said in Suricata on Pfsense:

                      Your suggestion is preferred, but from I understood from you, nobody is interested or have the knowledge.
                      Again thank you, for updating this package over the years.

                      I'm sure there is someone here on the forum using the package that has the knowledge to maintain it.

                      Another option if IDS/IPS is critical is to use the Linux package on a separate virtual machine or hardware appliance. Inline IPS performance would actually be very good using a Linux box (or even a FreeBSD box) with two separate NICs and configure true netmap hardware-to-hardware mode. That is many times more performant than the hardware-to-host mode that is required when using netmap within pfSense.

                      Of course using a separate box would mean no GUI, but that's how the vast majority of the world uses Suricata already (without a GUI).

                      1 Reply Last reply Reply Quote 0
                      • tinfoilmattT Offline
                        tinfoilmatt @btspce
                        last edited by

                        @btspce

                        Why isn't the pfsense supplied version following Suricata releases more closely?

                        The fading worthwhile use case of IDS/IPS aside, because it's not anyone-with-the-requisite-chops-to-keep-it-updated's priority, nor is it an official project package.

                        @bmeeks

                        I did send a detailed email a couple of weeks ago to the pfSense developer team letting them know of my retirement from package maintainer duties. They acknowledged receipt of the notice, so they are aware of the current package status (ditto for the Snort package, too).

                        End of an era. Thanks for all your contributions, Bill. You've done well more than the average bear.

                        1 Reply Last reply Reply Quote 0
                        • fireodoF Online
                          fireodo @bmeeks
                          last edited by

                          @bmeeks said in Suricata on Pfsense:

                          P.S. -- I did send a detailed email a couple of weeks ago to the pfSense developer team letting them know of my retirement from package maintainer duties. They acknowledged receipt of the notice, so they are aware of the current package status (ditto for the Snort package, too).

                          Hi Bill,

                          sad to see you "go", all the best for you, and a big THANKS for all you've done for Snort & Suricata!

                          Kind regards,
                          fireodo

                          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                          pfsense 2.8.1 CE
                          Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                          1 Reply Last reply Reply Quote 0
                          • bmeeksB Offline
                            bmeeks
                            last edited by bmeeks

                            Thanks guys! I'm not leaving pfSense nor the forum. I'm just retiring from active package maintenance.

                            I retired from my real job 11 years ago and I've been away from the cybersecurity industry long enough to be "out of date" with some of my knowledge 😀. Time to turn over the reins to the younger generation.

                            fireodoF JonathanLeeJ 2 Replies Last reply Reply Quote 2
                            • fireodoF Online
                              fireodo @bmeeks
                              last edited by

                              @bmeeks said in Suricata on Pfsense:

                              Time to turn over the reins to the younger generation.

                              I hope there will be a worthy successor 😉

                              Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                              SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                              pfsense 2.8.1 CE
                              Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                              1 Reply Last reply Reply Quote 0
                              • JonathanLeeJ Online
                                JonathanLee @bmeeks
                                last edited by JonathanLee

                                @bmeeks your work outclasses so many individuals and developers. Your stuff is amazing. Cheers

                                Make sure to upvote

                                S 1 Reply Last reply Reply Quote 1
                                • S Offline
                                  SteveITS Galactic Empire @JonathanLee
                                  last edited by

                                  FWIW there were two commits last week and 7.0.8_3 is available.

                                  Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                  When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                                  Upvote 👍 helpful posts!

                                  N 1 Reply Last reply Reply Quote 2
                                  • N Offline
                                    NRgia @SteveITS
                                    last edited by NRgia

                                    @btspce your redmine ticket was closed. It seems..."this is the way".

                                    Suricata binary 7.0.11 is now available. Thank you

                                    B 1 Reply Last reply Reply Quote 1
                                    • bmeeksB Offline
                                      bmeeks
                                      last edited by

                                      Just FYI -- upstream released 7.0.12 yesterday.

                                      1 Reply Last reply Reply Quote 1
                                      • B Offline
                                        btspce @NRgia
                                        last edited by

                                        @NRgia Saw that pfblockerng, suricata (7.0.11) and other packages had updates availible yesterday but when I went to do the updates a few hours later there was none to be found? Netgate seems to have pulled the updates for one reason or another.

                                        N S 2 Replies Last reply Reply Quote 0
                                        • N Offline
                                          NRgia @btspce
                                          last edited by NRgia

                                          @btspce I noticed those updates also, and they were pulled after some time. Maybe the code from Develop was pulled by mistake, and quickly removed.

                                          For Suricata, if you reinstall the package, 7.0.11 binary will be installed, instead of 7.0.8.

                                          Also I think we will need yet another ticket, for Suricata 7.0.12 as @bmeeks pointed out.

                                          B 1 Reply Last reply Reply Quote 0
                                          • B Offline
                                            btspce @NRgia
                                            last edited by

                                            @NRgia 7.0.12 has not landed in freshports yet. I will give Netgate a few days after that before creating a ticket.

                                            N 1 Reply Last reply Reply Quote 1
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.