• Snort Subscriber rules

    15
    0 Votes
    15 Posts
    2k Views
    bmeeksB
    @lucas1 said in Snort Subscriber rules: @NogBadTheBad It was: Downloading Snort Subscriber rules md5 file snortrules-snapshot-29120.tar.gz.md5... has become: Downloading Snort Subscriber rules md5 file snortrules-snapshot-29150.tar.gz.md5... Done downloading rules file. The reason was found by another employee. It's called try guess. Oh... you were not running the current version of the Snort binary. I assumed you were, so my mistake on that. The Snort team periodically ages out and discontinues rules support for older Snort versions. The rules are tied to specific binary versions, so you can't use the Snort rules from the 2.9.12 binary with the later 2.9.15 binary. So the moral of that story is keep your Snort package updated to the current version. I do my best to keep the Snort version in pfSense-RELEASE current so the rules downloads/updates will work. The 422 HTTP error was the Snort web site's roundabout way of saying that file version your Snort package was requesting was not present. Now, if you are using Snort Subscriber rules with Suricata, then it is your responsibility to log into the Snort rules web site periodically and check which version is current for the 2.9.x rules. You then have to manually configure Suricata to download the correct version. See this Sticky Post at the top of this forum: https://forum.netgate.com/topic/110325/using-snort-vrt-rules-with-suricata-and-keeping-them-updated. One big warning! DO NOT use the Snort 3.0 rules with Suricata! You will completely break your Suricata installation if you try that. The only way to recover it would be to remove it and install everything fresh again. Your post was a bit ambiguous as to whether you were running the Snort package or if you were running Suricata and using the Snort rules. I made an assumption that may have been incorrect.
  • Logs from a printer trying to communicate with lots of IP addresses

    4
    0 Votes
    4 Posts
    440 Views
    S
    Thank you so much guys for your reply. I will go ahead a disable the rule.
  • Pfsense Snort not blockig

    6
    0 Votes
    6 Posts
    832 Views
    bmeeksB
    @scorpoin said in Pfsense Snort not blockig: @NollipfSense said in Pfsense Snort not blockig: You said you just installed Snort...how do you know it's not blocking? Did you visited a site that's supposed to be blocked, yet you went to the site? Its not blocking when I try to connect my openvpn client it does connect me to my vpn server which suppose to be blocked as per rule? Regards The default Pass List will whitelist locally attached networks including your VPN. If you don't want that default action, then you will need to create your own custom pass list.
  • Snort start / FATAL ERROR:

    5
    0 Votes
    5 Posts
    2k Views
    bmeeksB
    Modbus is for industrial control systems. It is not used in business or home networks (typically).
  • Snort not detecting my interface (snort -W) on Windows 10

    windows 10 snort ids
    2
    1 Votes
    2 Posts
    1k Views
    bmeeksB
    This forum is for users of Snort on pfSense only. There is no support for Windows versions of Snort available here.
  • Suricata blocks traffic without alert

    7
    0 Votes
    7 Posts
    2k Views
    bmeeksB
    @mind12 said in Suricata blocks traffic without alert: @bmeeks said in Suricata blocks traffic without alert: 2024772 Never mind, that command just changed all the flowbit rules to alert using the dropsid.conf. I was confused by the name of the file dropsid.conf that it can't change anything to alert only to drop. It's the drop-down selector where you pick the file that determines the action (changes for drop, enable or modify) and not the filename. You can choose any file for the action and whatever matches the PCRE in that file produces are then used for finding and modifying rules.
  • [solved] how to activate Snort event pcaps?

    snort pcap
    6
    0 Votes
    6 Posts
    2k Views
    J
    For some reason, there're no pcap files in /var/log/snort/snort_*/ Log management tab is: [image: 1576593970049-cb7ae7d7-5e59-41f6-9bf5-31eed92ca9c7-image.png] Snort is running: [image: 1576594107551-ad0354a4-833a-4b9e-8f3b-d32c8bd015cb-image.png] Could anyone point me on how to enable them, please?
  • Snort how to choose rulesets/categories (level just above newbie)

    5
    0 Votes
    5 Posts
    1k Views
    M
    Thanks for your reply and your explanations. Even if it is not the answer I wished, it helps not loosing anymore time searching in a wrong direction. Thanks Have a nice day
  • Suricata 5.0 buzzing on Twitter

    14
    0 Votes
    14 Posts
    2k Views
    NollipfSenseN
    [image: 1576268521252-screen-shot-2019-12-13-at-2.20.10-pm.png]
  • Suricata crashing during Windows Server backup to backuppc by SMB

    12
    0 Votes
    12 Posts
    1k Views
    P
    Hello No more crash this weekend. I have launched a manual backup on friday to test and the memory usage hasn't increased. I will still wait for a week but I think the solution is good. Thanks a lot to @bmeeks for the help.
  • Snort Throughput Calculator

    2
    0 Votes
    2 Posts
    629 Views
    bmeeksB
    There are too many variables to make an accurate calculation in my view. Why not simply test it? You can turn on Performance Stats on the PREPROCESSORS tab and look through those log outputs to see where Snort is spending its time.
  • snort license

    3
    0 Votes
    3 Posts
    501 Views
    O
    @NogBadTheBad sir just wanting to make sure that there's no issue
  • 0 Votes
    7 Posts
    939 Views
    X
    Yes, it's for home. Thanks a lot for the detailed explanation, I am going to switch to LAN interface.
  • Snort-3.2.9.10 Package Update Release Notes

    8
    2 Votes
    8 Posts
    1k Views
    bmeeksB
    @bokikay said in Snort-3.2.9.10 Package Update Release Notes: Hello sir @bmeeks yesterday I run an upgrade to the latest one 3.2.9.10 for snort. It woks fine after I reboot my box. Today when I checked status it stops all and it looks like this pic. I click the play button to start the status but still it won work. Do I need to remove the package and reinstall it again? Thank you sir [image: 1574816418768-4325baac-1830-48fb-8b7e-0b3f966ba769-image.png] Have you looked in the pfSense system log to see what error messages are being logged when you attempt a restart of the interfaces? How do you expect me to help you if you give me no information to go on? I need error log messages to troubleshoot. I can't just sense what's wrong through the ether with "spidy senses" or something ... .
  • suricata update killing WAN interface

    4
    0 Votes
    4 Posts
    448 Views
    kiokomanK
    yes, of course
  • Snort error on 2.5

    1
    0 Votes
    1 Posts
    107 Views
    No one has replied
  • Suricata Not Blocking legacy mode

    76
    0 Votes
    76 Posts
    22k Views
    everfreeE
    Still waiting, hope it will be fixed.
  • Snort: Internet Radio Streams blocked

    9
    0 Votes
    9 Posts
    950 Views
    I
    @NogBadTheBad It is, I wrote before I thought.
  • Cant Update Rules

    3
    0 Votes
    3 Posts
    523 Views
    S
    Thank you so much (again:)...) It was the proxy that we use, my problem though was that I white-listed the wrong interface...
  • Suricata v4.1.4_7 Package Update Release Notes (pfSense-2.4.4_3)

    10
    1 Votes
    10 Posts
    967 Views
    bmeeksB
    I did forget to mention that when you clear out the /var/log/suricata directory that will wipe out all of the Suricata log files, so if you want those for some reason copy them off before executing the command.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.