Just confirmed I’m having a similar issue, I can’t get to the Internet using URL’s. According to the DNS settings, reverse DNS is completely failing on all my configured dns servers.
Not sure if I just found the problem, I changed DNS from TLS to TCP, clicked check DNS servers and then everything came back. Appears that there may be an issue with TLS in DNS. Internet pages are now loading through DNS.
Restarted, change settings, restarted again, still had issues with DNS failure even on TCP. Check the intrusion detection logs and saw a huge amount of outbound blocks due to what appear to be false positives. Disabled IPS and issue went away, unchecked DNS rules restarted IPS, still an issue. Only way it’s functional is with intrusion prevention turned off. Not entirely sure where the issue is coming from, will most likely have to downgrade until all the bugs are figured out in the next version.
The only way I was able to get working was to bypass the DNS Service of IPFire. I can confirm that the DNS Forwarding is not working correctly. First I went from DNS over TLS to DNS over UDP. It helped first but after a few seconds the DNS Queries weren’t able to be answered. Then I looked at this Forum and disabled the IPS but also this wont help (also after a few seconds the DNS Queries haven’t been responded). So I had to bypass the DNS by setting a fixed IP Address and setting the DNS Servers on my Client to Google (8.8.8.8 and 8.8.4.4). I also allowed the Traffic for this Client through the Firewall (because before I went through the Squid-Proxy). But it seems that not all services are working correctly on my client. but most of them.
Hi all,
same on my machine here. After Update von 164 everything looked okay initially. But after a few seconds tue web-gui stopped working. Now I am lost at the serial console of my ipfire- Box.
After stopping suricata from the console the web-gui ist accessible again.
Hopefully I can find which rules caused the trouble.
From the suricata log good candidates might be:
TRUFFLEHUNTER SFVRT-1045
FF-RAT
Jimini
1.php
Because all of these are generated from 3 different computers in my local Network running 3 different OS.
In addition, the IPS must be switched off completely (also via elinks). Please also uncheck Red, Green, Blue if necessary and save everything.
Then perform a reboot. Access to the WebGUI will work again, as well as the name resolution.
I have also tried after removing the option “Dropping” to enable the IPS again. Again, no name resolution occurs and the WebGUI is again inaccessible.
Apparently some rule is applied in the background that blocks access (GUI and name resolution).
I also have the following error message at boot time with IPS enabled. This does not appear with IPS disabled. Perhaps this will help narrow down the error:
However, another error at boot always appears regardless if with or without IPS:
Thanks for the elinks hint.
With my Installation it was enough to disable the registered-malware-cnc.rules in the IDS settings to make the system fully operational again.
I had the best idea in the morning to update during work, UI died quite soon during the update, checked from terminal that reboot was required, reboots did not help.
Recovered from fresh backup ISO (finally got disaster recovery tested).
Meanwhile i wiped and reinstalled core update 163. thank’s to the team that there will be made a backup of the system just before any upgrade. that really helps.