Please include the following information with your help request:
- 8.0.6 Suricata af-packet ips-copy
- Linux Mint Cinnamon latest release
- Source build in place
- 13900HK / 16Gb ddr4 3200 / Dual Intel 226v nics /
Creating a new thread to troubleshoot.
I removed the box from service after a few weird things were happening, and I think I solved them all but this.
Unit sits between a Firewalla Gold Plus and a D-Link DMS-1250-52x.
I loaded all the rules and got it functioning, but didn’t start dropping (so it was still basically IDS) and some of the PC’s would drop offline and not come back up without a reboot.
Even doing a disable/enable in windows and using netsh commands didn’t bring them back online.
Seems to happen when they’re online for over 3 hours and idle for at least an hour, they just drop and don’t come back.
Not sure where to look since the system should just be executing copies and not dropping packets (evebox says no drops)
When I pull the unit out and directly connect the firewalla to the switch, everything can go indefinitely with no disconnects.
Stumped on what could be doing this.