Project

General

Profile

Support #4409

Does the default Suricata 6 executable no longer supporting IPS mode on Windows?

Added by Bi. K. 4 months ago. Updated 4 months ago.

Status:
New
Priority:
Low
Assignee:
-
Affected Versions:
Label:

Description

The displayed error is "suricata: unknown option -- windivert".

"--windivert" option is recognized on Suricata 5 version.

#1

Updated by Peter Manev 4 months ago

It does. It is just a different package though as windivert seems to trigger a good few AV warnings when compiled in with it.
I am making an updated 6.0.2 with windivert now - would you be willing to try it out?

#2

Updated by Peter Manev 4 months ago

  • Tracker changed from Bug to Support
#3

Updated by Bi. K. 4 months ago

Yes Sir!
I will be.

#5

Updated by Bi. K. 4 months ago

I try to download the file but Google Drive blocks it.
Maybe beacuse it is an executable.

#6

Updated by Peter Manev 4 months ago

Ah yes - that problem exactly - gdrive for example detects the windivert part as malicious.
Can you try that instead

https://drive.google.com/file/d/1xAYGHKNivMw0Dn7UGABgfTFYlh-RbhmY/

#7

Updated by Bi. K. 4 months ago

I try the latest executable but, when launching the command to start Suricata, an error message says that "lua54.dll" is not found.

I will wait until the full release being available to try again.

Thank you!

Also available in: Atom PDF