Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Suricata 7.0.8_5 on pfsense 2.8.1 hangs after enabling [SOLVED]

    Scheduled Pinned Locked Moved IDS/IPS
    6 Posts 2 Posters 1.3k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      aGeekhere
      last edited by aGeekhere

      Wanted to test Suricata with a basic config
      Suricata 7.0.8_5 on pfsense 2.8.1 internet and network hangs after enabling, unbound service stops, ISC DHCP Server stops. I have to disable Suricata and reboot to fix it.

      Cannot seem to find the logs that shows what the issue is.

      Services Suricata Global Settings
      ETOpen is a free open source set of Suricata rules whose coverage is more limited than ETPro. - Checked
      Use a custom URL for ETOpen downloads - Checked
      Install Feodo Tracker Botnet C2 IP rules - Checked
      Install ABUSE.ch SSL Blacklist rules - Checked

      ETOpen Custom Rule Download URL
      https://rules.emergingthreats.net/open/suricata-7.0.8/emerging.rules.tar.gz

      Services Suricata LAN - Interface Settings
      Interface LAN
      Alert and Block Settings - Unchecked (doing IDS-only atm)

      Services Suricata Interface Settings LAN - Categories

      ONLY Feodo Tracker Botnet C2 IP Rules is checked

      AMD Ryzen 5 5600G with Radeon Graphics
      12 CPUs : 1 package(s) x 6 core(s) x 2 hardware threads
      AES-NI CPU Crypto: Yes (active)
      QAT Crypto: No
      Memory 16GB memory
      Ethernet Controller 10-Gigabit X540-AT2

      Hardware Checksum Offloading - Unchecked
      Hardware TCP Segmentation Offloading - Unchecked
      Hardware Large Receive Offloading - Unchecked
      hn ALTQ support - Checked

      I did leave it for 10 mins but the network was still down, not sure what i am doing wrong.

      Never Fear, A Geek is Here!

      A 1 Reply Last reply Reply Quote 0
      • A Offline
        aGeekhere @aGeekhere
        last edited by

        I still have this issue, when i enable Suricata unbound and dhcpd service crashes, only a restart can fix it after disabling Suricata and rebooting.

        Never Fear, A Geek is Here!

        1 Reply Last reply Reply Quote 0
        • bmeeksB Offline
          bmeeks
          last edited by bmeeks

          My best guess is your problem is hardware related and your specific Ethernet controller is the culprit. You problem seems specific to just your setup; otherwise, the forum would be flooded with similar messages about this issue as everyone runs unbound and dhcpd on their pfSense boxes and quite a few run Suricata.

          When Suricata starts up in IDS mode, the first thing it does is call the PCAP library to initiate a capture of traffic on the physical interface Suricata is configured to monitor. My educated guess is that sequence of events is disrupting the NIC driver in some manner. This would impact unbound and dhcpd because those daemons are tied to the underlying physical interface. If the network interface driver gets "stuck", then it stands to reason any other daemons bound to that interface will also experience problems.

          If you have a different NIC port to test (one that uses a different controller and driver), then try running Suricata there to see if it works. Also, unless you are running on a Hyper-V hypervisor, then you don't need the hn ALTQ support enabled.

          A 1 Reply Last reply Reply Quote 0
          • A Offline
            aGeekhere @bmeeks
            last edited by

            @bmeeks Will have a look through my settings and report back

            Never Fear, A Geek is Here!

            A 1 Reply Last reply Reply Quote 0
            • A Offline
              aGeekhere @aGeekhere
              last edited by

              Found the issue, rookie mistake,
              Hardware Checksum Offloading,
              Hardware TCP Segmentation Offloading,
              Hardware Large Receive Offloading
              Where not checked so they were enabled, forgot to check these to disable them.

              Never Fear, A Geek is Here!

              bmeeksB 1 Reply Last reply Reply Quote 0
              • bmeeksB Offline
                bmeeks @aGeekhere
                last edited by

                @aGeekhere said in Suricata 7.0.8_5 on pfsense 2.8.1 hangs after enabling [SOLVED]:

                Found the issue, rookie mistake,
                Hardware Checksum Offloading,
                Hardware TCP Segmentation Offloading,
                Hardware Large Receive Offloading
                Where not checked so they were enabled, forgot to check these to disable them.

                Glad you found the issue. I could not remember off the top of my head whether "unchecked" was enabled or disabled for those parameters, so sorry I missed that in my previous reply.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                Privacy Policy · Cookie Policy