Another update to my forked firmware:Leave TSO enabled for Linux AF_PACKET runmode
Code:suricata -c /opt/etc/suricata/suricata.yaml -i eth0 --set capture.disable-offloading=false
Could you update the release version with your changes?
Yes I agree. But I believe that it is necessary to open another topic. In this topic it is already certain that the IDS for Suricata is adequate and stable. It will leave the condition of experimental.Another update to my forked firmware:
Release 384.19 release 2 (GPL only) · faux123/asuswrt-merlin.ng
Added enhancements to Linux memory management and zswap subsystems to minimize kernel memory fragmentation for embedded systems (systems with low memory)github.com
BTW, snort3 is working well as IPS, should I release it? Do people want another IPS tool (it will have high load so a fan or an ice box is required and will slow down internet speed by a bit)?
Everybody don't have the chance to cap the hardware limit of the router as we don't all have fiber at home. I'm still on adsl with 16Mbps and prefer local security over bandwidth. We need profil like yours to give enhancements to the community. I want to thanks also rgnldo for his contributions to the subject. It is great to see such buddies in our community.. Thanks guys !Another update to my forked firmware:
Release 384.19 release 2 (GPL only) · faux123/asuswrt-merlin.ng
Added enhancements to Linux memory management and zswap subsystems to minimize kernel memory fragmentation for embedded systems (systems with low memory)github.com
BTW, snort3 is working well as IPS, should I release it? Do people want another IPS tool (it will have high load so a fan or an ice box is required and will slow down internet speed by a bit)?
I'm very interested to see of it works on my AX88U, yes please.BTW, snort3 is working well as IPS, should I release it? Do people want another IPS tool (it will have high load so a fan or an ice box is required and will slow down internet speed by a bit)?
The issues I had with IPV6 was related to the af_packet implementation of Suricata in IPS mode, I didn't look any further once I realized the bug in IPS mode. So I believe IDS mode is working fine esp with in pcap mode (which is the default if you followed the guided instructions).@faux123 what was the consensus here about using suricata as IPS only? too much for ac86?
can also confirm IDS doesn't work with IPv6...does that change for IPS/Native IPv6? anyone???
I did, but I'm not seeing any "action" on the graph/chart in the GUI.The issues I had with IPV6 was related to the af_packet implementation of Suricata in IPS mode, I didn't look any further once I realized the bug in IPS mode. So I believe IDS mode is working fine esp with in pcap mode (which is the default if you followed the guided instructions).
Yeah you currently have to run it directly from /jffs/addons/suricata.um, how does one make suricata_manager executable? I've issued it and all I get is
-sh: suricata_manager: not found
even though I've checked that it IS in the /jffs/addons/suricata folder
(could this be why my GUI graph isn't populating?)
It works. In IDS mode it is smooth and stable. Skynet + Suricata IDS, a good partnership.suitable for an RT-AC68U
I had to uninstall and reinstall, and it's all working again, even the chart in the GUI. so disregard my earlier support of the claim that suricata doesn't work under native IPv6Yeah you currently have to run it directly from /jffs/addons/suricata.
Just do "sh suricata_manager.sh <argument>" from the above directory.
Suricata by Entware, only IDS.
Thanks!It works. In IDS mode it is smooth and stable. Skynet + Suricata IDS, a good partnership.
wonderful, thank you.After running Suricata for a while now, I have today decided to disable some of the "noise" false positives. I disabled:
# - emerging-dns.rules
# - emerging-icmp_info.rules
# - emerging-user_agents.rules
# - emerging-policy.rules
# - emerging-games.rules
Policy items, tracking pings on the network, DNS lookups to more rarely used top level domains and interesting user agents, does seem to be worth the effort to filter through.
Added this change to the default yaml file and also updated the stats to group by day, making it easier to see items by day.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!