Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata silent timeouts in inline mode to specific http requests

    Scheduled Pinned Locked Moved IDS/IPS
    2 Posts 2 Posters 481 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      allu
      last edited by

      Hi all! I'm having issues with Suricata 4.0.4_1 running in inline mode on pfSense 2.4.3-RELEASE-p1.

      I'm running with a very large number of rules from Snort (paid) & the ET free. My issue is that some HTTP requests are randomly "blocked" without any warning/alert or other traceability... and by "blocked" I mean they are randomly timed out. If I stop the Suricata instance, the requests proceed normally without any issues.

      However with Suricata enabled, with for example request to this HTTP URL:
      http://korkeinoikeus.fi/js/public.js?timestamp=1530597609664
      0_1532000831532_Screen Shot 2018-07-19 at 14.45.56.png
      ...I get first few KBs worth of the Javascript and then nothing until the request times out.

      Any ideas how to debug which rule or if it is Suricata somehow causing the issue? Turning one rule off at a time and retesting is nearly impossible. I'm assuming there must be a buggy rule or another issue somewhere in Suricata that causes this, because of no alert being generated and the fact that it goes into a timeout instead of a forcibly closed connection? Again, I obviously checked that there are no suppressed warnings and such.

      1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire
        last edited by

        I suspect there's something wrong with inline mode as we've had cases where traffic doesn't flow but no alert is logged. See
        https://forum.netgate.com/topic/131572/moved-suricata-from-wan-to-lan-can-t-remote-desktop-in/10
        https://forum.netgate.com/topic/109581/suricata-inline-whitelisting/8

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.