[Oisf-users] Question about Suricata installation

Vi Le Quoc. Vo vi.vo.uh at rvc.renesas.com
Wed Jun 26 03:04:52 UTC 2013

Hi Julien,

1) I followed your guide (Add all options) but failed again. This is my command to configure Suricata
./configure --prefix=/usr/local/suricata --enable-nfqueue --with-libnetfilter_queue-includes=/usr/local/suricata-lib/include/ --with-libnetfilter_queue-libraries=/usr/local/suricata-lib/lib/ --with-libnfnetlink-includes=/usr/local/suricata-lib/include/ --with-libnfnetlink-libraries=/usr/local/suricata-lib/lib/

2) Error messages
checking libnetfilter_queue/libnetfilter_queue.h usability... yes
checking libnetfilter_queue/libnetfilter_queue.h presence... yes
checking for libnetfilter_queue/libnetfilter_queue.h... yes
checking for nfq_open in -lnetfilter_queue... no
checking for nfq_set_queue_maxlen in -lnetfilter_queue... no
checking for nfq_set_verdict2 in -lnetfilter_queue... no
checking for nfq_set_queue_flags in -lnetfilter_queue... no
checking for signed nfq_get_payload payload argument... no

   ERROR!  libnetfilter_queue library not found, go get it
   from www.netfilter.org.
   we automatically append libnetfilter_queue/ when searching
   for headers etc. when the --with-libnfq-includes directive
   is used

3) Before that I installed successfully libnfnetlink and libnetfilter_queue to /usr/local/suricata-lib/
./configure --prefix=/usr/local/suricata-lib

./configure --prefix=/usr/local/suricata-lib

I don't know what's wrong here


-----Original Message-----
From: oisf-users-bounces at openinfosecfoundation.org [mailto:oisf-users-bounces at openinfosecfoundation.org] On Behalf Of Victor Julien
Sent: Tuesday, June 25, 2013 5:59 PM
To: oisf-users at openinfosecfoundation.org
Subject: Re: [Oisf-users] Question about Suricata installation

Hash: SHA1

On 06/25/2013 12:55 PM, Eric Leblond wrote:
> Hi,
> Le mardi 25 juin 2013 à 12:51 +0200, Eric Leblond a écrit :
>> Hi,
>> Le mardi 25 juin 2013 à 17:04 +0700, Vi Le Quoc. Vo a écrit :
>>> Dear Julien,
>>> I send you the log file. Please help me to solve it. Thank you.
>> In your config.log you have $ ./configure --enable-nfqueue 
>> --with-libnetfilter_queue-includes=/usr/local/lib
>> --with-libnetfilter_queue-libraries=/usr/local/lib but you mentioned 
>> something like /usr/local/include/libnetfilter_queue/
>> in your first mail.
>> Please adjust the paths in --with-** to your system.
> By the way, --with-libnetfilter_queue-includes=/usr/local/lib is 
> usually something like 
> --with-libnetfilter_queue-includes=/usr/local/include

And don't forget:

- --with-libnfnetlink-includes=DIR  libnfnetlink include directory
- --with-libnfnetlink-libraries=DIR    libnfnetlink library directory

The error in the config log suggests it can't find nfnetlink:

configure:14588: checking for nfq_open in -lnetfilter_queue
configure:14613: gcc -o conftest -g -O2 -DRELEASE -Wextra -Wall
- -fno-strict-aliasing -fno-tree-pre -Wno-unused-parameter -std=gnu99
- -DNFQ  -I/usr/local/lib   -L/usr/local/lib conftest.c
- -lnetfilter_queue  -lnfnetlink -lpthread -lyaml -lpcre  >&5
/usr/local/lib/libnetfilter_queue.so: undefined reference to `mnl_attr_put'
/usr/local/lib/libnetfilter_queue.so: undefined reference to `mnl_attr_validate2'
/usr/local/lib/libnetfilter_queue.so: undefined reference to `mnl_attr_type_valid'
/usr/local/lib/libnetfilter_queue.so: undefined reference to `mnl_attr_parse'
/usr/local/lib/libnetfilter_queue.so: undefined reference to `mnl_attr_validate'
/usr/local/lib/libnetfilter_queue.so: undefined reference to `mnl_attr_put_u32'
/usr/local/lib/libnetfilter_queue.so: undefined reference to `mnl_attr_get_type'
collect2: ld returned 1 exit status

- --
- ---------------------------------------------
Victor Julien
PGP: http://www.inliniac.net/victorjulien.asc
- ---------------------------------------------

Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

Suricata IDS Users mailing list: oisf-users at openinfosecfoundation.org
Site: http://suricata-ids.org | Support: http://suricata-ids.org/support/
List: https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users
OISF: http://www.openinfosecfoundation.org/

More information about the Oisf-users mailing list