Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata 3.1.1 binary is now available for testing in 2.3.3 or 2.4 snapshots

    Scheduled Pinned Locked Moved IDS/IPS
    9 Posts 5 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bmeeksB
      bmeeks
      last edited by

      The new Suricata 3.1.1 binary package is available for testing for those of you that may have 2.3.3 or 2.4 snapshot installs.  The GUI package version is still 3.08, but the underlying binary is the newer 3.1.1 update.  Still testing for stability before we release this to the 2.3.2 production base.

      If you have a snapshot machine (virtual or real) and want to test out the new Suricata 3.1.1 update, please give it a shot and give me feedback on whether or not the problems with inline mode in the first release have been fixed or made better (or worse).

      To make sure you have the updated binary in a snapshot install, just remove the package and reinstall it.  You can verify the Suricata binary version on your box by executing this command from a shell prompt –

      
      suricata -V
      
      

      Bill

      1 Reply Last reply Reply Quote 0
      • M
        mikesamo
        last edited by

        Hello,

        do you have the link of the package I will test it on 2.3.2?

        Thanks,

        1 Reply Last reply Reply Quote 0
        • bmeeksB
          bmeeks
          last edited by

          @mikesamo:

          Hello,

          do you have the link of the package I will test it on 2.3.2?

          Thanks,

          It is not yet posted on the package repository for 2.3.2, so there is no link to provide.  If you have the URL for pfSense snapshots, you can find it in that repository.  You would need to manually download it and then install from the command line, but be ready for a lot of trial and error back and forth getting all the required dependent packages as well.  It's not as simple as just downloading one file and installing.  If you don't have a 2.3.3 or 2.4 snapshot, then I would suggest waiting for the official 2.3.2 posting to happen.

          Bill

          1 Reply Last reply Reply Quote 0
          • T
            Tantamount
            last edited by

            Bill,

            Cloned the vm of pfsense 2.3.2
            Enabled developer branch
            updated to 2.3.3
            rebooted
            installed Suricata 3.08 with 3.1.1_1
            enabled Suricata for WAN interface.
            started Suricata.

            Immediately started to see bad pkt errors on the console.

            Are you able to use inline without this happening? I'm just trying to determine if this is a configuration problem or not.

            2016-09-28_23-00-55.png
            2016-09-28_23-00-55.png_thumb

            1 Reply Last reply Reply Quote 0
            • N
              ntct
              last edited by

              It's the same error when installed with suricata 3.0_2.  :(

              I guess pfSense 2.3.x version may not have the opportunity to use inline mode now, maybe pfSense 2.4 has, because freebsd 11 have new version of netmap…..

              1 Reply Last reply Reply Quote 0
              • M
                mikesamo
                last edited by

                2.3.2 run inline very well.

                1 Reply Last reply Reply Quote 0
                • ?
                  Guest
                  last edited by

                  @mikesamo:

                  2.3.2 run inline very well.

                  Can you also try to enable inline mode for two interfaces? If I enable inline mode for WAN interface only, all is well, but when I enable for LAN interface also, I cannot connect to pfsense anymore, and any attempt to access any device on the LAN (pfsense included) is unsuccesful. The issue happens after 4-5 minutes.

                  My workaround is to enable inline mode, for one interface only….maybe it's Netmap related, I'll wait to see if FreeBsd 11 will fix this, or the new version of Suricata.

                  1 Reply Last reply Reply Quote 0
                  • M
                    mikesamo
                    last edited by

                    Hello,

                    work for me…

                    ![2016-09-30 12-45-39_Screenshot-2016-09-30_12.45.png](/public/imported_attachments/1/2016-09-30 12-45-39_Screenshot-2016-09-30_12.45.png)
                    ![2016-09-30 12-45-39_Screenshot-2016-09-30_12.45.png_thumb](/public/imported_attachments/1/2016-09-30 12-45-39_Screenshot-2016-09-30_12.45.png_thumb)

                    1 Reply Last reply Reply Quote 0
                    • ?
                      Guest
                      last edited by

                      @mikesamo:

                      Hello,

                      work for me…

                      That picture doesn't help, because in Legacy mode, it will look the same.

                      If you are in Inline mode for both Interfaces, I believe you, I'll try to delete the configuration for suricata by hand.

                      For me it only works for the second interface like bellow

                      Thanks

                      ![Services_ Suricata_ Edit Interface Settings - LAN.png_thumb](/public/imported_attachments/1/Services_ Suricata_ Edit Interface Settings - LAN.png_thumb)
                      ![Services_ Suricata_ Edit Interface Settings - LAN.png](/public/imported_attachments/1/Services_ Suricata_ Edit Interface Settings - LAN.png)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.