J
J
John_Alban2015-04-27 15:16:45
linux
John_Alban, 2015-04-27 15:16:45

IPS Snort and SPARC64 architecture, compatibility?

There was a following problem. There are a fairly large number of old SunFire X4100 servers (SPARC64 architecture), the idea arose to put them on IPS gateways / IDS sensors.
In summary, the solution looks like this:
--on Debian Wheezy (stable) servers --as
IPS/IPS - Snort 2.9.7.x version; installed from sources from snort.org -- for
IPS mode, DAQ is installed (also from sources)
-- the necessary bindings from pulledpork, barnyard2, mysql, snorby are installed
-- all this is configured in IPS mode (inline & DAQ nfq queues) and tested on virtualka
Problems began when setting up this bundle on SPARC .. Everything was compiled and installed without problems, auxiliary services (pulledpork, barnyard2, mysql, snorby) work as they should.
But Snort itself, after a packet for analysis arrives on it, crashes with a "bus error" error. And that's all. no more logs and information. Some problem with his preprocessors, apparently. Active googling did not give any results - this happened to people back in 2003-2006 - on the Debian bug tracker it is written that the problem is solved in new versions, so it should not be in wheezy. Changing the IP_TWIDDLE parameters in the decoders also did not give any results ..
Maybe someone faced the same result? Or can you give me some advice/help?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
J
John_Alban, 2015-04-30
@John_Alban

I close the question. My opinion is that snort will not work as IPS on SPARC64 architecture. No matter how I tried to revive it, it was useless. So I solved the problem simply - I transferred everything to the x86 server.
The only point is that I did not test IPS in pure briged mode (on SPARC). Maybe it will work, although I'm not sure. The feeling is that the problem is in the interaction of snort and DAQ drivers on SPARC, so if there is a SPARC, then it can only be used as an IDS sensor.

P
Puma Thailand, 2015-04-27
@opium

It seems that there are ready-made packages for spark
https://packages.debian.org/search?keywords=snort

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question