Suricata on IPSec VTI interface

if I start suricata via systemd, the following entries are written to suricata.log:

“ - [ERRCODE: SC_ERR_DATALINK_UNIMPLEMENTED(38)] - datalink type 768 not yet supported”

if I run suricata via cli, suricata works normally

suricata.yaml

af-packet:

  • interface: vti1

Could someone please advise?

Suricata v6.0.1
The main OS is Debian 11.6

Can you share the unit file configuration used when starting via systemd and also the command line used to start suricata from the cli?

JT

Thank you for your reply,
the problem was with af_packet mode, after changing to nfqueue everything works fine.

Tomas

1 Like