angolo40 / mikrocata2selks

Mikrotik + Selks (Suricata) + Telegram + TZSP on Debian 12
GNU General Public License v3.0
71 stars 16 forks source link

some problems on proxmox #4

Closed pitisk closed 11 months ago

pitisk commented 1 year ago

i have some problems on proxmox instalation debian11...

TZSP Replay crashing... error log on syslog:

Mar 11 02:57:36 ids-suricata systemd[1]: Stopped TZSP Replay on dev tzsp0. Mar 11 02:57:36 ids-suricata systemd[1]: Started TZSP Replay on dev tzsp0. Mar 11 02:57:38 ids-suricata sh[3002]: Fatal Error: Error editing packet #2975: From edit_packet.c:fix_ipv4_checksums() line 74: Mar 11 02:57:38 ids-suricata sh[3002]: Invalid packet: Expected IPv4 packet: got 0: pkt=2975 Mar 11 02:57:38 ids-suricata sh[3001]: error flushing via pcap_dump_flush Mar 11 02:57:38 ids-suricata systemd[1]: TZSPreplay@tzsp0.service: Main process exited, code=exited, status=255/EXCEPTION Mar 11 02:57:38 ids-suricata systemd[1]: TZSPreplay@tzsp0.service: Failed with result 'exit-code'. Mar 11 02:57:41 ids-suricata systemd[1]: TZSPreplay@tzsp0.service: Scheduled restart job, restart counter is at 3. Mar 11 02:57:41 ids-suricata systemd[1]: Stopped TZSP Replay on dev tzsp0. Mar 11 02:57:41 ids-suricata systemd[1]: Started TZSP Replay on dev tzsp0.

any help?

angolo40 commented 1 year ago

Never tested on proxmox sorry

angolo40 commented 11 months ago

The official recommendation from Proxmox is to use a VM for better security. There is some concern that if the Docker instance is compromised, this could allow an attacker to breach the Proxmox host as well.