Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata Starts then Stops!

    Scheduled Pinned Locked Moved 2.5 Development Snapshots (Retired)
    6 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NollipfSenseN
      NollipfSense
      last edited by NollipfSense

      Suricata has issue with Netmap while Snort doesn't have any issue at all. So, it appears something to do with Suricata. Here is the message from Suricata log:

      /5/2020 -- 00:01:08 - <Error> -- [ERRCODE: SC_ERR_NETMAP_CREATE(263)] - Couldn't query netmap for igb0, error Invalid argument
      1/5/2020 -- 00:01:08 - <Info> -- Going to use 1 thread(s)
      1/5/2020 -- 00:01:08 - <Error> -- [ERRCODE: SC_ERR_NETMAP_CREATE(263)] - opening devname netmap:igb0/R failed: Invalid argument

      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

      1 Reply Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense
        last edited by

        Correction ... it is both Suricata, and Snort in inline mode has the problem with Netmap; so, the problem is Netmap.

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        1 Reply Last reply Reply Quote 0
        • bmeeksB
          bmeeks
          last edited by

          Aware and looking into the issue. It is most likely related to the move to FreeBSD-12.1-STABLE for the latest snapshots.

          NollipfSenseN 1 Reply Last reply Reply Quote 0
          • NollipfSenseN
            NollipfSense @bmeeks
            last edited by

            @bmeeks Thanks Bill, meanwhile, both are running in legacy mode.

            pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
            pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

            1 Reply Last reply Reply Quote 0
            • bmeeksB
              bmeeks
              last edited by

              Try this. It worked for me in my testing VM.

              1. Remove the Suricata package using SYSTEM > PACKAGE MANAGER.

              2. Return to SYSTEM > PACKAGE MANAGER and install the Suricata package again.

              This will forcibly download and reinstall all the new FreeBSD-12.1-STABLE libraries that Suricata needs.

              Let me know if this works or not.

              NollipfSenseN 1 Reply Last reply Reply Quote 0
              • NollipfSenseN
                NollipfSense @bmeeks
                last edited by

                @bmeeks Well, Bill, I had a wild Sunday morning with pfSense 2.5-devel 20200502-210 ... for some unknown reason, after the update; WAN would not load completing the boot process. I find that odd given I was running legacy mode. So, I decided to do a fresh install, update, and restore from backup.

                The install and update went well ... as soon as I restore from backup, on rebooting, it stops ... WAN would not load. So, really wanting to preserve the configuration, I went through process fresh install, update and restore from a week earlier than the first. Same thing WAN would not load to compete the boot.

                Ended, freshly install, update and fresh configuration. Suricata and Snort inline mode is working ... still more configuration to do however, this time I'll keep it simpler. Thank you for following up.

                pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.