Suricata true inline IPS mode coming with pfSense 2.3 – here is a preview
-
A quick fix for the missing Barnyard2 binary was posted today by the pfSense team. If you remove and then reinstall Suricata, it should bring along Barnyard2 now like it did in the past.
Bill
-
There has been nothing new on this project in many months. Is it dead? I certainly hope not, but I assume we are waiting on improvements to netmap which hasn't been updated in quite a while. Suricata 3.1.1 is out now and seems to be in current development.
I could really use this package as I am sure many others are chomping at the bit for it.
Progress preview maybe?
Dan
-
I guess this really is a dead project after all. It's a real shame.
-
This desperately needs to happen… I need Inline mode so bad, I can't describe how badly I need it. We have so much junk traffic tossed at valid IPs that perfectly good sites get blocked and many web/cloud based tools that my faculty and staff depend on become useless.
I've tuned Suricata rules until I can't see straight, and still, valid sites get blocked.
Come on devs, roll this stuff out! We are all rooting for you (and whining a bit).
Suricata 3.1.1 has been out for a while now in production, I wonder if there are still underlying netmap/driver issues causing problems with Inline mode?
-
I installed suricata, and the installer complained about some mysql client vulnerability that will not be patched. Something to be worried about?
-
@<deleted>:</deleted>
Suricata package has been updated today from 3.0_7 to 3.0_8.
From the changelogs I see only a fix for "Suricata, a broken download should not wait forever." ,and some changes in licenses.
@bmeeks I don't understand, why not jumping to the latest version, with latest fixes, because they are alot ?
10x
I have been very busy with other work outside of my volunteer package maintainer duties for Suricata and Snort. The other work pays me, the volunteer maintainer duties do not … ;).
I am testing the latest 3.1.1 binary this weekend and hope to have a pull request posted very soon.
Bill
-
Will inline IDS be working with the latest Suricata update?
-
Will inline IDS be working with the latest Suricata update?
Hopefully better than it currently does. The issues are pretty much all netmap related as netmap is a relatively new technology. Suricata has had some upstream bugs reported around the netmap interface used for inline mode. A lot of those reported issues are fixed in the 3.1.1 release.
Bill
-
Thank you @BMeeks!
Looks like there's an updated Suricata in Package Manager with the latest 3.1.1_1 version. Trying it out now!
-
Does latest suricata 3.1.1_1 support hyperscan pattern match ?
-
-
2.3.3_dev
-
-
Does latest suricata 3.1.1_1 support hyperscan pattern match ?
It's not turned on yet. That is next on my list to test. Not sure what kinds of tweaking may be required in FreeBSD ports to get that enabled and compiling successfully.
Bill
-
I will give inline mode a go again when Suricata 3.1.1 becomes available.
-
Available now… for pfSense 2.3.3x and 2.4 development versions. Not the pfSense stable, yet.
Version 3.0.8 of Suricata for pfSense contains the Suricata 3.1.1_1 update - the pfSense implementation hasn't been up-rev'd.
-
2.3.2-p1 is the latest version according to my dashboard. I do not risk using development versions. Pfsense is in a production environment.
-
Lately, when I ask for status on Inline Suricata, the thread gets deleted. What's up with that? I thought this was a community forum.
I will attempt more questions
Is it in testing?
How is the testing going?
What are the issues?
Why is PFsense so far behind in Suricata updates?
How many people are working on it?
Do you need testers, or help?
Is there an ETA?
Should I move on?I guess the last question depends on if this post also gets deleted, or I get banned for asking questions.
-
You should probably move on and do IPS on a dedicated machine running a hardend version of your favorite OS.
It's not a priority on pfSense (for now) and if you haven't setup a full blown SIEM solution it's anyway a toy ;-).Regarding your questions, just search through the forum and you'll find your answers.
Regards,
Emanuel
-
Not the first time I have seen that reply about a SIEM… one has nothing to do with the other. Wanting Suricata working in inline mode on my firewall is completely unrelated to a SIEM and is definitely not relegated to "toy" status in the absense of a SIEM. I'd love to have a serious discussion (off of the forum if necessary to reduce clutter) about this as I am not trying to throw rocks or start a flame war. I just don't grok the relationship between running Suricata in inline mode and having or not having a SIEM.