<div dir="ltr"><div>For reference here is my NIC init script. </div><div>The linked wiki page mentions that issues like this can be related to the NIC queues and a changed packet order.<br></div><div>Would it be safe to ignore these rules then? </div><div><br></div><div><br></div><div><div>ethtool -K enp17s0f1 tso off</div><div>ethtool -K enp17s0f1 gro off</div><div>ethtool -K enp17s0f1 ufo off</div><div>ethtool -K enp17s0f1 lro off</div><div>ethtool -K enp17s0f1 gso off</div><div>ethtool -K enp17s0f1 rx off</div><div>ethtool -K enp17s0f1 tx off</div><div>ethtool -K enp17s0f1 sg off</div><div>ethtool -K enp17s0f1 rxvlan off</div><div>ethtool -K enp17s0f1 txvlan off</div><div>ethtool -N enp17s0f1 rx-flow-hash udp4 sdfn</div><div>ethtool -N enp17s0f1 rx-flow-hash udp6 sdfn</div><div>ethtool -C enp17s0f1 rx-usecs 1 rx-frames 0</div><div>ethtool -C enp17s0f1 adaptive-rx off</div><div>ethtool -L enp17s0f1 combined 1</div></div><div><br></div><div><br></div><div><div>ethtool -l enp17s0f1</div><div>Channel parameters for enp17s0f1:</div><div>Pre-set maximums:</div><div>RX:             0</div><div>TX:             0</div><div>Other:          1</div><div>Combined:       63</div><div>Current hardware settings:</div><div>RX:             0</div><div>TX:             0</div><div>Other:          1</div><div>Combined:       1</div></div><div><br></div><div><div>modinfo ixgbe</div><div>filename:       /lib/modules/4.0.5-gentoo/kernel/drivers/net/ethernet/intel/ixgbe/ixgbe.ko</div><div>version:        4.0.1-k</div></div><div><br></div><div>NIC is:</div><div>Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection <br></div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On 12 July 2016 at 20:16, Marius <span dir="ltr"><<a href="mailto:mciepluch@web.de" target="_blank">mciepluch@web.de</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div class="gmail_extra">I'm on 4.0.5-gentoo. </div><div><div class="h5"><div class="gmail_extra"><br></div><div class="gmail_extra"><br><div class="gmail_quote">On 12 July 2016 at 20:01, Victor Julien <span dir="ltr"><<a href="mailto:lists@inliniac.net" target="_blank">lists@inliniac.net</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span>On 12-07-16 21:55, Cooper F. Nelson wrote:<br>
> What kernel version are you using?<br>
><br>
> There is a bug in the 4.2 and higher Linux kernel versions with the RSS<br>
> implementation.  I was seeing those issues and reverting to the 4.1<br>
> release fixed it.<br>
<br>
</span>That bug is still there, it's fixed in kernel 4.7rc7 and hopefully the<br>
fix will be backported to stable kernels.<br>
<br>
This post may be helpful as well<br>
<a href="https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Packet_Capture" rel="noreferrer" target="_blank">https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Packet_Capture</a><br>
<span><br>
<br>
><br>
> -Coop<br>
><br>
> On 7/12/2016 12:46 PM, Marius wrote:<br>
>> The rules, which indicate an error, are mostly stream engine related:<br>
>> SURICATA STREAM 3way handshake with ack in wrong dir [Classification:<br>
>> (null)]<br>
>> SURICATA STREAM ESTABLISHED packet out of window<br>
>> SURICATA STREAM ESTABLISHED invalid ack<br>
>> SURICATA STREAM Packet with invalid ack<br>
>> SURICATA STREAM FIN invalid ack<br>
><br>
><br>
><br>
><br>
</span>> _______________________________________________<br>
> Suricata IDS Users mailing list: <a href="mailto:oisf-users@openinfosecfoundation.org" target="_blank">oisf-users@openinfosecfoundation.org</a><br>
> Site: <a href="http://suricata-ids.org" rel="noreferrer" target="_blank">http://suricata-ids.org</a> | Support: <a href="http://suricata-ids.org/support/" rel="noreferrer" target="_blank">http://suricata-ids.org/support/</a><br>
> List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users" rel="noreferrer" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users</a><br>
> Suricata User Conference November 9-11 in Washington, DC: <a href="http://oisfevents.net" rel="noreferrer" target="_blank">http://oisfevents.net</a><br>
><br>
<span><font color="#888888"><br>
<br>
--<br>
---------------------------------------------<br>
Victor Julien<br>
<a href="http://www.inliniac.net/" rel="noreferrer" target="_blank">http://www.inliniac.net/</a><br>
PGP: <a href="http://www.inliniac.net/victorjulien.asc" rel="noreferrer" target="_blank">http://www.inliniac.net/victorjulien.asc</a><br>
---------------------------------------------<br>
<br>
_______________________________________________<br>
Suricata IDS Users mailing list: <a href="mailto:oisf-users@openinfosecfoundation.org" target="_blank">oisf-users@openinfosecfoundation.org</a><br>
Site: <a href="http://suricata-ids.org" rel="noreferrer" target="_blank">http://suricata-ids.org</a> | Support: <a href="http://suricata-ids.org/support/" rel="noreferrer" target="_blank">http://suricata-ids.org/support/</a><br>
List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users" rel="noreferrer" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users</a><br>
Suricata User Conference November 9-11 in Washington, DC: <a href="http://oisfevents.net" rel="noreferrer" target="_blank">http://oisfevents.net</a></font></span></blockquote></div><br></div></div></div></div><div class="HOEnZb"><div class="h5"><div class="gmail_extra"><br><div class="gmail_quote">On 12 July 2016 at 20:01, Victor Julien <span dir="ltr"><<a href="mailto:lists@inliniac.net" target="_blank">lists@inliniac.net</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span>On 12-07-16 21:55, Cooper F. Nelson wrote:<br>
> What kernel version are you using?<br>
><br>
> There is a bug in the 4.2 and higher Linux kernel versions with the RSS<br>
> implementation.  I was seeing those issues and reverting to the 4.1<br>
> release fixed it.<br>
<br>
</span>That bug is still there, it's fixed in kernel 4.7rc7 and hopefully the<br>
fix will be backported to stable kernels.<br>
<br>
This post may be helpful as well<br>
<a href="https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Packet_Capture" rel="noreferrer" target="_blank">https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Packet_Capture</a><br>
<span><br>
<br>
><br>
> -Coop<br>
><br>
> On 7/12/2016 12:46 PM, Marius wrote:<br>
>> The rules, which indicate an error, are mostly stream engine related:<br>
>> SURICATA STREAM 3way handshake with ack in wrong dir [Classification:<br>
>> (null)]<br>
>> SURICATA STREAM ESTABLISHED packet out of window<br>
>> SURICATA STREAM ESTABLISHED invalid ack<br>
>> SURICATA STREAM Packet with invalid ack<br>
>> SURICATA STREAM FIN invalid ack<br>
><br>
><br>
><br>
><br>
</span>> _______________________________________________<br>
> Suricata IDS Users mailing list: <a href="mailto:oisf-users@openinfosecfoundation.org" target="_blank">oisf-users@openinfosecfoundation.org</a><br>
> Site: <a href="http://suricata-ids.org" rel="noreferrer" target="_blank">http://suricata-ids.org</a> | Support: <a href="http://suricata-ids.org/support/" rel="noreferrer" target="_blank">http://suricata-ids.org/support/</a><br>
> List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users" rel="noreferrer" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users</a><br>
> Suricata User Conference November 9-11 in Washington, DC: <a href="http://oisfevents.net" rel="noreferrer" target="_blank">http://oisfevents.net</a><br>
><br>
<span><font color="#888888"><br>
<br>
--<br>
---------------------------------------------<br>
Victor Julien<br>
<a href="http://www.inliniac.net/" rel="noreferrer" target="_blank">http://www.inliniac.net/</a><br>
PGP: <a href="http://www.inliniac.net/victorjulien.asc" rel="noreferrer" target="_blank">http://www.inliniac.net/victorjulien.asc</a><br>
---------------------------------------------<br>
<br>
_______________________________________________<br>
Suricata IDS Users mailing list: <a href="mailto:oisf-users@openinfosecfoundation.org" target="_blank">oisf-users@openinfosecfoundation.org</a><br>
Site: <a href="http://suricata-ids.org" rel="noreferrer" target="_blank">http://suricata-ids.org</a> | Support: <a href="http://suricata-ids.org/support/" rel="noreferrer" target="_blank">http://suricata-ids.org/support/</a><br>
List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users" rel="noreferrer" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users</a><br>
Suricata User Conference November 9-11 in Washington, DC: <a href="http://oisfevents.net" rel="noreferrer" target="_blank">http://oisfevents.net</a></font></span></blockquote></div><br></div>
</div></div></blockquote></div><br></div>