I’m fairly certain this is a hardware issue, but wanted to check here to make sure there isn’t anything specific to Suricata that I should troubleshoot before going and replacing the NIC…Recently, I can’t have Suricata running for more than 24 hours before this happens (suricata.log):
21/8/2023 -- 16:45:16 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:45:24 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:45:25 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:45:34 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:45:34 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:45:37 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:45:50 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:45:51 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:45:55 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:45:55 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:46:01 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:46:05 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:46:07 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
21/8/2023 -- 16:46:10 - <Error> - [ERRCODE: SC_ERR_AFP_READ(191)] - Error reading data from iface 'ixgbe2': (100) Network is down
Immediately prior to Suricata logging the interface is down, this appears in dmesg:
[Mon Aug 21 16:44:50 2023] ixgbe 0000:01:00.0: removed PHC on ixgbe2
[Mon Aug 21 16:44:50 2023] ixgbe 0000:01:00.0: registered PHC device on ixgbe2
[Mon Aug 21 16:44:50 2023] IPv6: ADDRCONF(NETDEV_UP): ixgbe2: link is not ready
[Mon Aug 21 16:44:50 2023] ixgbe 0000:01:00.0 ixgbe2: detected SFP+: 4
[Mon Aug 21 16:44:53 2023] ixgbe 0000:01:00.0 ixgbe2: NIC Link is Up 10 Gbps, Flow Control: RX/TX
[Mon Aug 21 16:44:53 2023] IPv6: ADDRCONF(NETDEV_CHANGE): ixgbe2: link becomes ready
Anything I can/should look at in Suricata to troubleshoot this? We’ve been running on the same system with the same config for years now without issue, which is making me lean toward a hardware issue…
This is Suricata 6.0.13 in af-packet mode, running on fully patched CentOS 7.
TIA!