Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata Inline Mode and Online Bank Deposit

    Scheduled Pinned Locked Moved IDS/IPS
    6 Posts 2 Posters 894 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NollipfSenseN
      NollipfSense
      last edited by

      So, I attempted to deposit a check into my bank account and got the following on the PFSense monitor screen:

      196.115874 [1071] netmap_grab_packets  bad pkt at 445 1en 2164

      I wasn't sure what's going on; so, I switch to the legacy mode because I needed to make the deposit.  I was using my phone to make the deposit. After the deposit completed, I change to inline mode again.  Also, Barnyard2 still wouldn't start despite making the necessary configuration changes in Advance >networking.

      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        @NollipfSense:

        So, I attempted to deposit a check into my bank account and got the following on the PFSense monitor screen:

        196.115874 [1071] netmap_grab_packets  bad pkt at 445 1en 2164

        I wasn't sure what's going on; so, I switch to the legacy mode because I needed to make the deposit.  I was using my phone to make the deposit. After the deposit completed, I change to inline mode again.  Also, Barnyard2 still wouldn't start despite making the necessary configuration changes in Advance >networking.

        This is not malicious traffic.  It simply means the netmap interface between your NIC driver and kernel is not liking something in the stream.  Most likely some incompatibility issue or perhaps a bug in the netmap code.  Several folks have reported that error with inline IPS mode.

        Bill

        1 Reply Last reply Reply Quote 0
        • NollipfSenseN
          NollipfSense
          last edited by

          @bmeeks:

          @NollipfSense:

          So, I attempted to deposit a check into my bank account and got the following on the PFSense monitor screen:

          196.115874 [1071] netmap_grab_packets  bad pkt at 445 1en 2164

          I wasn't sure what's going on; so, I switch to the legacy mode because I needed to make the deposit.  I was using my phone to make the deposit. After the deposit completed, I change to inline mode again.  Also, Barnyard2 still wouldn't start despite making the necessary configuration changes in Advance >networking.

          This is not malicious traffic.  It simply means the netmap interface between your NIC driver and kernel is not liking something in the stream.  Most likely some incompatibility issue or perhaps a bug in the netmap code.  Several folks have reported that error with inline IPS mode.

          Bill

          Thank you Bill for responding…I didn't think it was anything malicious...I had implemented the inline mode Monday night; so, I wasn't sure whether the check image transfer happened.

          pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
          pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks
            last edited by

            I should also note that the error message is being generated by the FreeBSD kernel code (specifically the netmap module) and not Suricata.  You might want to report this upstream to the FreeBSD folks.

            Bill

            1 Reply Last reply Reply Quote 0
            • NollipfSenseN
              NollipfSense
              last edited by

              @bmeeks:

              I should also note that the error message is being generated by the FreeBSD kernel code (specifically the netmap module) and not Suricata.  You might want to report this upstream to the FreeBSD folks.

              Bill

              Glad you followed up Bill…I had attempted to fine tune the NIC via here: https://doc.pfsense.org/index.php/Tuning_and_Troubleshooting_Network_Cards...it seems to help for a while until I started getting igb1 watchdog timeout and eventually the same netmap_grab_packets  bad pkt. My NIC is Intel dual gigabit PCle 82575 and I went back to legacy mode despite not having any freezing or other weird behavior with PFsense or Suricata during the inline mode.

              How do I report upstream to FreeBSD...they don't seem to accept anyone who mentioned PFSense?

              pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
              pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

              1 Reply Last reply Reply Quote 0
              • NollipfSenseN
                NollipfSense
                last edited by

                Okay Bill…found it...FreeBSD Bugzilla – Bug 226289 Submitted...Bug 226289 has been successfully created.

                pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.