https://redmine.pfsense.org/https://redmine.pfsense.org/favicon.ico?16780521162019-06-02T19:23:46ZpfSense bugtrackerpfSense Packages - Bug #9573: GeoIP database FAIL to download - Suricata packagehttps://redmine.pfsense.org/issues/9573?journal_id=408252019-06-02T19:23:46ZBill Meeks
<ul></ul><p>You do not need to do anything to use the free GeoIP2 Lite database with Suricata on pfSense. It is automatically set up at package installation and a daily update cron job is created to keep the database updated from that point forward. This assumes you are using the free version of the GeoIP2 Lite database.</p>
<p>The database you are trying to download has been deprecated by MaxMind. GeoIP has been replaced by GeoIP2. The new database has a completely new internal format and is incompatible with applications that used the old GeoIP format. Suricata was updated for the 4.1.2 release to use the GeoIP2 database.</p>
<p>If you have a paid GeoIP2 database subscription and corresponding code from MaxMind, then post back and I can post some detailed instructions on how to hanlde that with the Suricata package. It will take manual editing of some files. Otherwise, remove the package you installed that provided the <em>/usr/local/bin/geoipupdate.sh</em> script. It is not needed for Suricata 4.1.4 on pfSense.</p> pfSense Packages - Bug #9573: GeoIP database FAIL to download - Suricata packagehttps://redmine.pfsense.org/issues/9573?journal_id=408372019-06-03T21:47:05ZCarlos Montalvo J.
<ul></ul><p>Hi, Bill</p>
<p>I´m sorry but suricata is the one installing package GeoIP-1.6.12.</p>
Only the following packages are installed on my pfSense:
<ul>
<li>Avahi v2.0.0_2</li>
<li>Filer v0.60.6_1</li>
<li>lldpd v0.9.9</li>
<li>pfBlockerNG v2.1.4_17</li>
<li>Service_Watchdog v1.8.6</li>
<li>Suricata v4.1.4</li>
</ul>
<p>Here is a copy of a the install output following the WebGUI, after I removed Suricata and proceed to reinstall. (Also suricata should display all required dependencies not just barnyard2)</p>
<blockquote><blockquote><blockquote>
<p>Installing pfSense-pkg-suricata...</p>
</blockquote></blockquote></blockquote>
<p>Updating pfSense-core repository catalogue...<br />pfSense-core repository is up to date.<br />Updating pfSense repository catalogue...<br />pfSense repository is up to date.<br />All repositories are up to date.<br />Checking integrity... done (0 conflicting)<br />The following 14 package(s) will be affected (of 0 checked):</p>
<p>New packages to be INSTALLED:<br /> pfSense-pkg-suricata: 4.1.4 [pfSense]<br /> suricata: 4.1.4 [pfSense]<br /> libyaml: 0.1.6_2 [pfSense]<br /> nss: 3.39 [pfSense]<br /> nspr: 4.20 [pfSense]<br /> libpcap: 1.8.1 [pfSense]<br /> libnet: 1.1.6_5,1 [pfSense]<br /> py27-yaml: 5.1 [pfSense]<br /> hyperscan: 4.6.0 [pfSense]<br /> hiredis: 0.13.3 [pfSense]<br /> barnyard2: 1.13_1 [pfSense]<br /> broccoli: 1.97,1 [pfSense]<br /> <strong>GeoIP: 1.6.12 [pfSense]</strong>++<br /> mysql56-client: 5.6.41 [pfSense]</p>
<p>Number of packages to be installed: 14</p>
<p>The process will require 76 MiB more space.<br />[1/14] Installing nspr-4.20...<br />[1/14] Extracting nspr-4.20: .......... done<br />[2/14] Installing GeoIP-1.6.12...<br />[2/14] Extracting GeoIP-1.6.12: .......... done<br />[3/14] Installing libyaml-0.1.6_2...<br />[3/14] Extracting libyaml-0.1.6_2: ......... done<br />[4/14] Installing nss-3.39...<br />[4/14] Extracting nss-3.39: .......... done<br />[5/14] Installing libpcap-1.8.1...<br />[5/14] Extracting libpcap-1.8.1: .......... done<br />[6/14] Installing libnet-1.1.6_5,1...<br />[6/14] Extracting libnet-1.1.6_5,1: .......... done<br />[7/14] Installing py27-yaml-5.1...<br />[7/14] Extracting py27-yaml-5.1: .......... done<br />[8/14] Installing hyperscan-4.6.0...<br />[8/14] Extracting hyperscan-4.6.0: .......... done<br />[9/14] Installing hiredis-0.13.3...<br />[9/14] Extracting hiredis-0.13.3: .......... done<br />[10/14] Installing broccoli-1.97,1...<br />[10/14] Extracting broccoli-1.97,1: .......... done<br />[11/14] Installing mysql56-client-5.6.41...<br />[11/14] Extracting mysql56-client-5.6.41: .......... done<br />[12/14] Installing suricata-4.1.4...<br />[12/14] Extracting suricata-4.1.4: .......... done<br />[13/14] Installing barnyard2-1.13_1...<br />[13/14] Extracting barnyard2-1.13_1: ...... done<br />[14/14] Installing pfSense-pkg-suricata-4.1.4...<br />[14/14] Extracting pfSense-pkg-suricata-4.1.4: .......... done<br />Saving updated package information...<br />done.<br />Loading package configuration... done.<br />Configuring package components...<br />Loading package instructions...<br />Custom commands...<br />Executing custom_php_install_command()...Saved settings detected...<br />Migrating settings to new configuration... done.<br />Downloading Emerging Threats Open rules md5 file... done.<br />There is a new set of Emerging Threats Open rules posted. Downloading... done.<br />Downloading Snort GPLv2 Community Rules md5 file... done.<br />There is a new set of Snort GPLv2 Community Rules posted. Downloading... done.<br />Installing Emerging Threats Open rules... done.<br />Installing Snort GPLv2 Community Rules... done.<br />Updating rules configuration for: WAN ... done.<br />Cleaning up after rules extraction... done.<br />The Rules update has finished.<br />Generating suricata.yaml configuration file from saved settings.<br />Generating YAML configuration file for WAN... done.<br />Finished rebuilding Suricata configuration from saved settings.<br /> Setting package version in configuration file.<br />done.<br />Executing custom_php_resync_config_command()...done.<br />Menu items... done.<br />Services... done.<br />Writing configuration... done.<br />Message from GeoIP-1.6.12:</p>
GeoIP does not ship with the actual data files. You must download<br />them yourself! To obtain the free database, run:
<ol>
<li>/usr/local/bin/geoipupdate.sh<br />Message from mysql56-client-5.6.41:</li>
</ol>
<ul>
<li>* * * * * * * * * * * * * * * * * * * * * * *</li>
</ul>
<p>Please be aware the database client is vulnerable<br />to CVE-2015-3152 - SSL Downgrade aka "BACKRONYM".<br />You may find more information at the following URL:</p>
<p><a class="external" href="http://www.vuxml.org/freebsd/36bd352d-299b-11e5-86ff-14dae9d210b8.html">http://www.vuxml.org/freebsd/36bd352d-299b-11e5-86ff-14dae9d210b8.html</a></p>
<p>Although this database client is not listed as<br />"affected", it is vulnerable and will not be<br />receiving a patch. Please take note of this when<br />deploying this software.</p>
<ul>
<li>* * * * * * * * * * * * * * * * * * * * * * *<br />Message from suricata-4.1.4:</li>
</ul>
<p>===========================================================================</p>
<p>If you want to run Suricata in IDS mode, add to /etc/rc.conf:</p>
<pre><code>suricata_enable="YES" <br /> suricata_interface="&lt;if&gt;"</code></pre>
<p>NOTE: Declaring suricata_interface is MANDATORY for Suricata in IDS Mode.</p>
<p>However, if you want to run Suricata in Inline IPS Mode in divert(4) mode,<br />add to /etc/rc.conf:</p>
<pre><code>suricata_enable="YES" <br /> suricata_divertport="8000"</code></pre>
<p>NOTE:<br /> Suricata won't start in IDS mode without an interface configured.<br /> Therefore if you omit suricata_interface from rc.conf, FreeBSD's<br /> rc.d/suricata will automatically try to start Suricata in IPS Mode<br /> (on divert port 8000, by default).</p>
<p>Alternatively, if you want to run Suricata in Inline IPS Mode in high-speed<br />netmap(4) mode, add to /etc/rc.conf:</p>
<pre><code>suricata_enable="YES" <br /> suricata_netmap="YES"</code></pre>
<p>NOTE:<br /> Suricata requires additional interface settings in the configuration<br /> file to run in netmap(4) mode.</p>
<p>RULES: Suricata IDS/IPS Engine comes without rules by default. You should<br />add rules by yourself and set an updating strategy. To do so, please visit:</p>
<pre><code><a class="external" href="http://www.openinfosecfoundation.org/documentation/rules.html">http://www.openinfosecfoundation.org/documentation/rules.html</a><br /> <a class="external" href="http://www.openinfosecfoundation.org/documentation/emerging-threats.html">http://www.openinfosecfoundation.org/documentation/emerging-threats.html</a></code></pre>
<p>You may want to try BPF in zerocopy mode to test performance improvements:</p>
<pre><code>sysctl -w net.bpf.zerocopy_enable=1</code></pre>
<p>Don't forget to add net.bpf.zerocopy_enable=1 to /etc/sysctl.conf</p>
<p>===========================================================================<br />Message from barnyard2-1.13_1:</p>
<p>Read the notes in the barnyard2.conf file for how to configure<br />/usr/local/etc/barnyard2.conf after installation. For addtional information<br />see the Securixlive FAQ at <a class="external" href="http://www.securixlive.com/barnyard2/faq.php">http://www.securixlive.com/barnyard2/faq.php</a>.</p>
<p>In order to enable barnyard2 to start on boot, you must edit /etc/rc.conf<br />with the appropriate flags, etc. See the FreeBSD Handbook for syntax:<br /><a class="external" href="http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/configtuning-rcng.html">http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/configtuning-rcng.html</a></p>
<p>For the various options available, type % barnyard2 -h after install or read<br />the options in the startup script - in /usr/local/etc/rc.d.</p>
<p>Barnyard2 can process unified2 files from snort or suricata. It can also<br />interact with snortsam firewall rules as well as the sguil-sensor. Those<br />ports must be installed separately if you wish to use them.</p>
<hr />
<blockquote><blockquote><blockquote>
<p>Cleaning up cache... done.</p>
</blockquote></blockquote></blockquote>
<p>Success</p>
<p>--<br />Bill Meeks wrote:</p>
<blockquote>
<p>You do not need to do anything to use the free GeoIP2 Lite database with Suricata on pfSense. It is automatically set up at package installation and a daily update cron job is created to keep the database updated from that point forward. This assumes you are using the free version of the GeoIP2 Lite database.</p>
<p>The database you are trying to download has been deprecated by MaxMind. GeoIP has been replaced by GeoIP2. The new database has a completely new internal format and is incompatible with applications that used the old GeoIP format. Suricata was updated for the 4.1.2 release to use the GeoIP2 database.</p>
<p>If you have a paid GeoIP2 database subscription and corresponding code from MaxMind, then post back and I can post some detailed instructions on how to hanlde that with the Suricata package. It will take manual editing of some files. Otherwise, remove the package you installed that provided the <em>/usr/local/bin/geoipupdate.sh</em> script. It is not needed for Suricata 4.1.4 on pfSense.</p>
</blockquote> pfSense Packages - Bug #9573: GeoIP database FAIL to download - Suricata packagehttps://redmine.pfsense.org/issues/9573?journal_id=408382019-06-03T21:56:27ZBill Meeks
<ul></ul><p>Hmm... looks like it is getting pulled in as a dependency, probably with a library.</p>
<p>No matter, you still do not use it as it won't be properly configured. The pfSense installation of Suricata will trigger an internal Suricata script that will download the proper database and place it in <strong>/usr/local/share/suricata/GeoLite2/</strong>. The filename should be <em>GeoLite2-Country.mmdb</em> and it should show a recent date. The free database is updated once per month, I believe, so the date could be one month old or slightly more.</p>
<p>The file that installs the database and then keeps it updated is <em>/usr/local/pkg/suricata/suricata_geoipupdate.php</em>. That file is run once during package installation and then is set up as a daily cron task.</p>
<p>That message you are seeing is the default post-install messages that are part of the upstream FreeBSD port. They really have no relevance when you run one of the pfSense GUI packages like Suricata or Snort.</p> pfSense Packages - Bug #9573: GeoIP database FAIL to download - Suricata packagehttps://redmine.pfsense.org/issues/9573?journal_id=411842019-08-13T10:00:59ZBill Meeks
<ul></ul><p>I do not believe this represents an actual bug in the Suricata package. The user was attempting to follow one of the numerous ost-installation prompts written to the package installation log screen by the <em>pkg</em> process. The Suricata package has internal code that downloads the proper free GeoIP2 database upon package installation and configures it for use. The report here is about the ancillary manual download script package installed as a dependency by the <em>libmaxminddb</em> libary. However, that script package is not used, nor is it required, by Suricata. It was the manual download script that exhibited the error posted by the user.</p>
<p>This issue can be either closed or rejected as a bug report.</p>
<p>Bill Meeks</p> pfSense Packages - Bug #9573: GeoIP database FAIL to download - Suricata packagehttps://redmine.pfsense.org/issues/9573?journal_id=411922019-08-13T10:04:41ZJim Pingle
<ul><li><strong>Status</strong> changed from <i>New</i> to <i>Rejected</i></li></ul>