Project

General

Profile

Actions

Bug #16808

open

During re-install or update, suricata re-enables rules that were disabled

Added by COMPUTECH Micro Design about 8 hours ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Suricata
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
26.03
Affected Architecture:
SG-2100, arm64

Description

Whenever suricata is re-installed, or updated (i.e. after it was previously installed and configured), it re-enables all the "Ruleset: Default Rules" rulesets/categories in all interfaces, even though it retains all the other rulesets/categories enable/disable settings.

This is a significant issue, particularly on updates, because as those rules seem to be mostly informational, when they get re-enabled especially on an interface that has blocking turned on, it causes problems, and I'm guessing that many users don't know or remember to go in and turn them back off after a pfSense/suricata update. An update (or re-install) should not change existing settings/configuration without a warning/explanation notification/popup).

No data to display

Actions

Also available in: Atom PDF