Project

General

Profile

Actions

Support #4409

open

Does the default Suricata 6 executable no longer supporting IPS mode on Windows?

Added by Bi. K. 6 months ago. Updated 6 months ago.

Status:
New
Priority:
Low
Assignee:
-
Affected Versions:
Label:

Description

The displayed error is "suricata: unknown option -- windivert".

"--windivert" option is recognized on Suricata 5 version.

Actions #1

Updated by Peter Manev 6 months ago

It does. It is just a different package though as windivert seems to trigger a good few AV warnings when compiled in with it.
I am making an updated 6.0.2 with windivert now - would you be willing to try it out?

Actions #2

Updated by Peter Manev 6 months ago

  • Tracker changed from Bug to Support
Actions #3

Updated by Bi. K. 6 months ago

Yes Sir!
I will be.

Actions #5

Updated by Bi. K. 6 months ago

I try to download the file but Google Drive blocks it.
Maybe beacuse it is an executable.

Actions #6

Updated by Peter Manev 6 months ago

Ah yes - that problem exactly - gdrive for example detects the windivert part as malicious.
Can you try that instead

https://drive.google.com/file/d/1xAYGHKNivMw0Dn7UGABgfTFYlh-RbhmY/

Actions #7

Updated by Bi. K. 6 months ago

I try the latest executable but, when launching the command to start Suricata, an error message says that "lua54.dll" is not found.

I will wait until the full release being available to try again.

Thank you!

Actions

Also available in: Atom PDF