Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata inline mode breaking barnyard2

    Scheduled Pinned Locked Moved IDS/IPS
    2 Posts 1 Posters 514 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hyperg0at
      last edited by

      Howdy, I was experimenting with inline blocking mode and somehow this has managed to break the integration with barnyard2. Now barnyard2 refuses to start with the following error:

      FATAL ERROR: [ParseSidMapLine()], File [/usr/local/etc/suricata/suricata_47561_igb0/sid-msg.map], Error in map definition [1 || 1000001 ||  || NOCLASS || 0 || Pass List Entry - allow all traffic from/to 10.10.10.1/32] for value []
      

      This does not occur on other interfaces with barnyard2 turned on and seems to be isolated to the WAN interface.

      Any ideas on further troubleshooting or remediation steps? Thanks!

      1 Reply Last reply Reply Quote 0
      • H
        hyperg0at
        last edited by

        So I made some progress on this; the issue is that suricata is not properly generating the passlist rules for sid-msg.map (it's omitting a 'rev' column) which I think is what is tripping up barnyard2.

        I was able to disable/enable blocking to get the passlist entries no longer added to the .map file, but it seems like they get put back in if I switch over to inline.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.