Intrusion Prevention System will not run - Core 161

I just upgraded to the 64-bit architecture Core-161 by doing a full installation. I then applied the backed-up configuration. So now I am using 2.27(x86_64) Core Update 161.

After full install the Intrusion Prevention system shows as “stopped” looking at the status on the system terminal (/etc/init.d/suricata status) it shows that indeed it is not running.

On the web interface there are no settings options to start the IPS or to set the interfaces. Attempting to start the system from the command line provides no response other than a new command line.

Any suggestions as to why this is not/will not run and why the settings options are not available in the web interface?

Thanks,
-Craig

Problem resolved. It is necessary first to save a rule set before any options appear or the IPS can be started or configured.

Has the Snort ruleset available using an oinkcode gone away?

1 Like

Hi,

glad you managed to solve this yourselves. :slight_smile:

It is necessary first to save a rule set before any options appear or the IPS can be started or configured.

Ah yes, there is also bug #12051 for this… :expressionless:

Has the Snort ruleset available using an oinkcode gone away?

No, but the oinkcode field is only displayed if a ruleset source requires a registration or subscription.

(Also, we do not use Snort anymore, but Suricata.)

Thanks, and best regards,
Peter Müller

1 Like