opnsense / opnsense/src

26.7(.1): Suricata configuration causes crashes

Open
#306 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C
Stars
505
Forks
202
PR merge metrics
No merged PRs in 30d

Description

Important notices

Before you add a new report, we ask you kindly to acknowledge the following:

Describe the bug

Prior to 26.7, Suricata was fine. Updating to 26.7 caused crashes where OPNSense would boot, and within a minute or two, a cascade of text would fill the screen, then the host miniPC for OPNSense would reboot and the cycle would restart.

Utilizing option 4 on the shell to reset to default configuration eliminates the issue.

During Suricata configuration process for 26.7.1, the bug returned, forcing another reset to default configuration.

To Reproduce

Steps to reproduce the behavior (upgrade):

  1. Have Suricata installed on pre-26.7 OPNSense.
  2. Complete update process to 26.7
  3. Have hardware running OPNSense connected to monitor
  4. Load into shell
  5. Wait ~1-2 minutes
  6. Cascade of text
  7. Crash
  8. System reboots
  9. Wait ~1-2 minutes
  10. Crash loop continues

Steps to reproduce the behavior (Suricata config on 26.7 - speculative):

  1. Enable Suricata IPS
  2. Set capture mode to Netmap
  3. Press "Download & Update Rules"
  4. Crashing begins sometime afterwards

Expected behavior

Suricata on 26.7(.1) to function normally and not interfere with OPNSense functionality.

Describe alternatives you considered

Setting Suricata to Divert mode might prevent the issue, but I haven't tried it.

Additional context

OPNSense is configured as a transparent filtering bridge.

Environment

OPNsense 26.7(.1) (amd64).
Intel® N100
Network Intel® WiFi 6 AX101

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the Suricata IPS and Netmap configuration described in the reproduction steps, using shell option 4 to compare the default configuration with the failing one. Capture the cascade of text before the reboot and narrow the failure to the 26.7(.1) upgrade or configuration process. Done means Suricata runs without crashes or reboot loops on the stated bridge setup.

Written by the indexing model from the issue text.

Assessment

Tech stack
c
Domain
networking, operating-systems, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.