Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata Inline Mode Issue

    Scheduled Pinned Locked Moved IDS/IPS
    7 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JSONSec
      last edited by

      Hey All,

      Over this Easter break I built myself a new pfsense box with a lot more horse power than my first. Its now packing an Intel i5, 8GB RAM, and a quad port Intel 82580 NIC coupled with a Draytek Vigor 130.

      Everything is working perfectly, except when I try to run Suricata in inline mode. When I disable hardware checksum and enable it, within 5 to 15 mins it drops the connection to the Draytek and I get 100% packetloss. Reverse the change and everything works as expected.

      Not really sure how to progress this and would appreciate any help.

      Thanks,
      J.

      1 Reply Last reply Reply Quote 0
      • P
        pfBasic Banned
        last edited by

        Yeah I also can't get online mode to work with two different supported NICs. It seems got our miss on the forums. I haven't seen any definitive answers as to why either.

        I think the general answer is that netmap is just young and still in the process of working out its issues.

        1 Reply Last reply Reply Quote 0
        • J
          JSONSec
          last edited by

          Ok, at least I'm not the only one. It's been driving me nuts.  :)

          1 Reply Last reply Reply Quote 0
          • K
            keelingj
            last edited by

            Are you using the Traffic Shaper?  Suricata breaks it in Inline mode…

            C2758 8-core Atom
            32GB ECC RAM
            100GB Intel DC S3700

            1 Reply Last reply Reply Quote 0
            • J
              JSONSec
              last edited by

              I am using traffic shapers! I should remove it and try again?

              1 Reply Last reply Reply Quote 0
              • P
                pfBasic Banned
                last edited by

                You can try it but I'm not convinced it will help.

                I've tried it without the traffic shaper on both a PRO/1000 and an i340 and neither worked.

                1 Reply Last reply Reply Quote 0
                • J
                  Jens76
                  last edited by

                  Bug #6690: SURICATA IPS Issue - Kills VLANS & Traffic Shaper
                  https://redmine.pfsense.org/issues/6690

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.