Project

General

Profile

Actions

Support #4409

closed

Does the default Suricata 6 executable no longer supporting IPS mode on Windows?

Added by Bi. K. about 3 years ago. Updated about 2 years ago.

Status:
Closed
Priority:
Low
Assignee:
-
Affected Versions:
Label:

Description

The displayed error is "suricata: unknown option -- windivert".

"--windivert" option is recognized on Suricata 5 version.

Actions #1

Updated by Peter Manev about 3 years ago

It does. It is just a different package though as windivert seems to trigger a good few AV warnings when compiled in with it.
I am making an updated 6.0.2 with windivert now - would you be willing to try it out?

Actions #2

Updated by Peter Manev about 3 years ago

  • Tracker changed from Bug to Support
Actions #3

Updated by Bi. K. about 3 years ago

Yes Sir!
I will be.

Actions #5

Updated by Bi. K. about 3 years ago

I try to download the file but Google Drive blocks it.
Maybe beacuse it is an executable.

Actions #6

Updated by Peter Manev about 3 years ago

Ah yes - that problem exactly - gdrive for example detects the windivert part as malicious.
Can you try that instead

https://drive.google.com/file/d/1xAYGHKNivMw0Dn7UGABgfTFYlh-RbhmY/

Actions #7

Updated by Bi. K. about 3 years ago

I try the latest executable but, when launching the command to start Suricata, an error message says that "lua54.dll" is not found.

I will wait until the full release being available to try again.

Thank you!

Actions #8

Updated by Andreas Herz about 2 years ago

  • Status changed from New to Closed

Hi, we're closing this issue since there have been no further responses.
If you think this issue is still relevant, try to test it again with the
most recent version of suricata and reopen the issue. If you want to
improve the bug report please take a look at
https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Reporting_Bugs

Actions

Also available in: Atom PDF