StamusNetworks / SELKS

A Suricata based IDS/IPS/NSM distro

Home Page:https://www.stamus-networks.com/open-source/#selks

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

πŸžπŸ‹ <Can't update the sources of suricata. How can I connect to the internet with proxy?>

Linn1 opened this issue Β· comments

commented

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

I set ftp,http,https proxy and when I choose to add public source on the web page, it failed to add. The error was "Temporary failure in name resolution". I cannot see any public source on the page. But I tried to curl the rule file on the server, I found that the file can be download. It seems that the scirius doesn't know that I use the proxy to connect to the internet.
I enter the scirius container and try to curl the rule file. But the container seems cannot connect to the internet.
I set the proxy in file "/etc/profile". And the system proxy is worked. But how to tell scirius I use the proxy to manage suricata rules?

Expected Behavior

I can add public sources and update these sources.

Steps To Reproduce

No response

Docker version

Docker version 20.10.14, build a224086

Docker version

docker-compose version 1.29.2, build 5becea4c

OS Version

Description: Debian GNU/Linux 11 (bullseye)

Content of the environnement File

COMPOSE_PROJECT_NAME=SELKS
INTERFACES= -i enp3s0f1
ELASTIC_MEMORY=8G
SCIRIUS_SECRET_KEY=

Version of SELKS

commit fb84874 (HEAD -> master, origin/master, origin/HEAD)
Author: Eric Leblond el@stamus-networks.com
Date: Wed Apr 6 11:28:47 2022 +0200

Anything else?

No response

Is it a dns problem ?
What kind of a proxy do you have setup?

commented

I add the ftp/http/https proxy to the /etc/profile as root and I can run wget to download the tar file. But I can't update the ruleset on the web page. I don't know why. I suspect that because I didn't set the proxy of the scirius.

commented

I choose to use system proxy when I update the source. But it still show the error "Temporary failure in name solution". I don't know how to tell the scirius that I use proxy .

You can set it up from the GUI directly. I would suggest to remove the cmd changes you've done , and try the GUI, like so:

Screenshot from 2022-09-29 17-52-58

commented

Yes!! I can set it up from GUI directly and it worked!Thanks!