Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata Pfsense 2.2.2

    Scheduled Pinned Locked Moved IDS/IPS
    2 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      ghkrauss
      last edited by

      Gentlemen:

      A heads up with respect to Suricata. I have Suricata the most current verison (Pfsense Package List) installed. It does not seem to run correctly with Pfsense 2.2.2. It installs, updates, a shows to be running but registers no alerts in a period of hours. We have a 100 M/s fiber connect so there is more than ample traffic. I reverted to Pfsense 2.2 and apparent normal operation returns.

      I have and additional question. When using Pfsense 2.2 and Suricata the following alerts are produced

      SURICATA STREAM ESTABLISHED retransmission packet before last ack

      Show I add these to a suppress list? What caused this repeating messages? Can I fix this issue?

      Thanks for any help

      G. Howard Krauss

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        @ghkrauss:

        Gentlemen:

        A heads up with respect to Suricata. I have Suricata the most current verison (Pfsense Package List) installed. It does not seem to run correctly with Pfsense 2.2.2. It installs, updates, a shows to be running but registers no alerts in a period of hours. We have a 100 M/s fiber connect so there is more than ample traffic. I reverted to Pfsense 2.2 and apparent normal operation returns.

        I have and additional question. When using Pfsense 2.2 and Suricata the following alerts are produced

        SURICATA STREAM ESTABLISHED retransmission packet before last ack

        Show I add these to a suppress list? What caused this repeating messages? Can I fix this issue?

        Thanks for any help

        G. Howard Krauss

        That alert is from the Suricata stream processor.  You will the triggering rule and many others in the stream-events.rules file (look on the CATEGORIES tab and then select stream-events in the drop-down).  You can disable that rule and any others that you consider false positives or noise.  Suricata is extraordinarily chatty with these stream alerts.

        Bill

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.