Project

General

Profile

Actions

Bug #15018

open

Suricata 7.0.2 service stop problem

Added by Robert Karsai 6 months ago. Updated 6 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Suricata
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
2.7.1
Affected Plus Version:
23.09
Affected Architecture:

Description

Hello,

I can't reliably stop Suricata service using Services / Suricata / Interfaces / <interface> / stop icon. I've got about 50-60% chance that the service will restart itself somehow in a minute instead of stopping. I've got the same results in CLI using "/usr/local/etc/rc.d/suricata.sh stop". Also: the restart icon sometimes starts a second instance of Suricata (even when there is only one interface in the Suricata interface list), but I guess there might be the same issue behind this.

It's not a new behaviour, I've experienced those things on Suricata 6 in the previous pfSense release and now also in pfSense+ 23.0.9 and pfSense CE 2.7.1 with Suricata 7.0.2. It may be hardware (CPU) related, I think it happens more frequently on lower end devices (like on Netgate 4100), seen this several times on Protecli VP2420s, but never seen on Netgate 8200 or on Netgate 1537.

BR
--
Robert


Files

Screenshot from 2023-11-26 22-31-37.png (291 KB) Screenshot from 2023-11-26 22-31-37.png Events when Suricata restart occurs Robert Karsai, 11/26/2023 09:46 PM
Actions

Also available in: Atom PDF