Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata Running on Interface Will Not Stop

    Scheduled Pinned Locked Moved IDS/IPS
    4 Posts 3 Posters 450 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      newUser2pfSense
      last edited by

      I'm doing a little troubleshooting trying to figure out which Suricata rule I enabled that's stopping communication for one of my iPhone apps. I decided to go to Services > Suricata > Interfaces tab and in the Interface Settings Overview > Suricata Status column, I pressed the "Stop suricata on this interface" button. Interestingly, Suricata will stop running on the interface for only a very short period of time and then seemingly restart itself. Not only from the GUI, but from the command prompt by running: ps -ax | grep suricata, I can see the interface stop and then re-enable itself. Is there a way to get Suricata to stop restarting itself automagically or is this a feature 🤔 ? Any suggestions would be most helpful. Thank you.

      1 Reply Last reply Reply Quote 0
      • kiokomanK
        kiokoman LAYER 8
        last edited by

        nope, i'm using suricata on 2.4.5 and 2.5.0, when I stop suricata it does not restart automatically.
        idk, maybe you have another package like watchdog ?

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        1 Reply Last reply Reply Quote 0
        • N
          newUser2pfSense
          last edited by

          I'm presently on 2.4.5. I actually had to edit the interface and uncheck Enable and then click Save to get it to stop completely. When I did this, I was able to do my troubleshooting. After, I Enabled and Saved it again. I don't have any other packages that would have restarted it. Odd! Just thought I would ask if anyone else experienced the same. Thanks for the reply.

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks
            last edited by

            Suricata will not restart itself except when it does an automatic rules update. The binary has no mechanism to even accomplish this. The PHP GUI code takes care of restarting Suricata after a rules update download.

            pfSense will, under some circumstances, issue a "restart all packages" command. Could that have been going on at the same time you were trying to stop Suricata? Very unusual if that were the case, though.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.