Suricata4-4.1.7_2 (for SG-1000 and SG-3100 Netgate Appliances)
bmeeks last edited by
Suricata4-4.1.7_2 Release Notes
Note: this version of Suricata is based on the 4.x binary is exclusively for use on Netgate SG-1000 and SG-3100 devices (with armv6 or armv7 CPUs).
This update randomizes the periodic rules update check to spread the load on the rules update sites due to the large number of pfSense Suricata installations. The former default value had large numbers of machines hitting the rules update sites at precisely 5 minutes past the midnight hour local time.
The Rules Update Start Time on the GLOBAL SETTINGS tab now has a random minute for the default start time for first-time users.
For existing users who have never changed their Rules Update Start Time from the old default of 00:05, the minutes value will be randomized and stored.
The PHP module that performs the actual rules update check will randomly sleep for between 0 and 35 seconds before actually making connection to the Snort.org site.