@etian90:
Hi guys, I´m having the same problems with my snort, I can´t update my rules. do you know how I can do it manual? thanks
What error message is being printed in the log file viewable on the UPDATES tab in Snort? There are basically only three things that go wrong here and those are:
1. You are running pfBlockerNG and one of its IP address lists included the IP address pool of the Amazon Web Services network used by the Snort VRT to host their rule downloads. That is probably the most common cause of this problem. If you are using pfBlockerNG, disable it while attempting Snort rules updates.
2. You have the OpenAppID rules download enabled but you are located in a country which is being blocked by GeoIP rules from accesing the university web site in Brazil that hosts the free OpenAppID rules download package. If this is the case, you simply can't use those rules unless you can use a VPN so that you can appear to be coming from a different non-Geo Blocked country.
3. Rarely, the Snort VRT folks have a problem with their automated system that posts the rules package files. Sometimes the MD5 does not get updated or is missing entirely. If this is the problem, it will fix itself soon.
Reading the error message you will find in the Rules Update Log will help you figure out which of the above three common problems you are experiencing. If the message in your logs is something else, then post the entire message back here and we will see how to proceed.
You can't update the rules manually with the Snort package on pfSense. Too much stuff has to happen in a concerted fashion to make that practical.
Bill