Getting error after setting Suricata as a IPS

Hello everyone,

i’m new to suricata and i’m trying to configure suricata as an IPS. On my suricata.log i get the following error:

10/2/2022 -- 11:57:05 - <Error> - [ERRCODE: SC_ERR_FATAL(171)] - nfq_unbind_pf() for AF_INET failed

On /etc/sysconfig/suriocata i set this:

OPTIONS="-q0"

I do not undestand why is this happening. Can someone please help with this? Thank you in advance.

Best regards

cb0n3y

Hi,

Have you configured iptables for NFQUEUE ?

https://suricata.readthedocs.io/en/suricata-6.0.4/setting-up-ipsinline-for-linux.html

Hello Suricatalfon,

sorry for the late answer and thank you for your response. No, i didn’t configure iptables for NFQUEUE yet. I will give a try and i let you know. Thank you again.

Regards

cb0n3y

1 Like