[Oisf-users] Suricata - Write to ipfw divert socket failed

Özkan KIRIK ozkan.kirik at gmail.com
Wed Mar 5 22:17:31 UTC 2014


I'm using FreeBSD 10 ipfw and ipdivert enabled.
I tried suricata v.1.4.6, v1.4.7 and also 2.0rc1.

All versions throws this error sometimes "<Warning> - [ERRCODE:
SC_WARN_IPFW_XMIT(84)] - Write to ipfw divert socket failed: Permission
After a while, thread restart threshold exceeded and suricata completely

I was diverted only 1 host to suricata. But still gives this error.

It's strange, I inspected the source-ipfw.c file. The problem about
injecting packet back to divert socket.

errno = 13 - EACCESS.

I saw that SO_BROADCAST option was set to socket.

How can i debug this situation, or any solutions?

Best regards
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20140306/fff17f29/attachment.html>

More information about the Oisf-users mailing list