Project

General

Profile

Actions

Bug #8576

closed
RM

Suricata stops processing packets when receiving via GRE/ERSPAN

Bug #8576: Suricata stops processing packets when receiving via GRE/ERSPAN

Added by Richard McConnell about 2 months ago. Updated 4 days ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

An issue was identified with Suricata 8 where it would stop working as expected, reporting 0 packetRate and no longer producing payloads.
From investigation, the issue looks to only affect instances where suricata receives GRE or ERSPAN encapsulated traffic although only a 20% of these are affected.
We have been unable to reproduce this in our lab setting

From our investigation within our product we found:
  • Normal behaviour would return after a restart, normally triggered by the weekly rules release, then stop some random amount of time after
  • This has occurred across a number of different OS - ubuntu 24.04, rhel 8.10, rhel 9.5 etc

JI Updated by Jason Ish about 2 months ago ยท Edited Actions #1

This may be fixed in 8.0.5, just released today.

JF Updated by Juliana Fajardini Reichow about 1 month ago Actions #2

  • Status changed from New to Feedback

Hi @Richard McConnell could you please confirm whether this is fixed with 8.0.5 release?

RM Updated by Richard McConnell 11 days ago Actions #4

Hi @Juliana Fajardini Reichow, I can confirm we're not observing this issue now in v8.0.5 release. We consider this bug fixed! Thanks very much :)

JF Updated by Juliana Fajardini Reichow 4 days ago Actions #5

  • Status changed from Feedback to Resolved

Marking as resolved, as per the reporter's comment.
Tackled by the related ticket.

JF Updated by Juliana Fajardini Reichow 4 days ago Actions #6

  • Status changed from Resolved to Closed
Actions

Also available in: PDF Atom