• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Problems with Suricata in pfSense on Proxmox running inline mode

Scheduled Pinned Locked Moved IDS/IPS
4 Posts 2 Posters 366 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    Bob.Dig LAYER 8
    last edited by Bob.Dig Apr 24, 2024, 8:20 AM Apr 24, 2024, 8:20 AM

    vtnet should be supported by inline mode and while it is running flawlessly on a pfSense VM in the oracle cloud free tier using this driver, I had no luck running it at home on my proxmox, there is no connectivity after enabling it. So maybe I am missing something?

    1 Reply Last reply Reply Quote 0
    • B
      bmeeks
      last edited by bmeeks Apr 24, 2024, 12:09 PM Apr 24, 2024, 12:05 PM

      If it runs on a pfSense VM in one hypervisor (or virtual environment), then I would hazard a guess that the failure to run in another (Proxmox in your case) points to a problem with vtnet emulation in that hypervisor.

      Translated -- I suspect a problem with vtnet within Proxmox, and thus there is nothing wrong nor nothing to fix on the pfSense side since other hypervisors have no problem with vtnet drivers and IPS Inline Mode in pfSense.

      In my experience here on the Netgate forum over the years, I've seen the most "issues" with hypervisors and pfSense when the hypervisor is either Hyper-V or Proxmox. I've seen the fewest issues when it was VMware (either Workstation or ESXi).

      B 1 Reply Last reply Apr 24, 2024, 2:32 PM Reply Quote 1
      • B
        Bob.Dig LAYER 8 @bmeeks
        last edited by Apr 24, 2024, 2:32 PM

        @bmeeks Hyper-V doesn't use vtnet so sure, it won't run.

        But maybe someone else has it running without a problem and I only have to tweak "something".

        B 1 Reply Last reply Apr 24, 2024, 2:41 PM Reply Quote 0
        • B
          bmeeks @Bob.Dig
          last edited by bmeeks Apr 24, 2024, 2:42 PM Apr 24, 2024, 2:41 PM

          @Bob-Dig said in Problems with Suricata in pfSense on Proxmox running inline mode:

          Hyper-V doesn't use vtnet so sure, it won't run.

          I didn't mean to imply Hyper-V supported vtnet. Only mentioned Hyper-V because a number of other issues have been surfaced there by users attempting to run pfSense. My point was that these two hypervisors (Hyper-V and Proxmox) tend to show up most often when someone posts with a pfSense issue in a virtual environment. I notice much fewer issues posted when virtualizing pfSense in a VMware environment.

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received