• Can't start Snort interface

    3
    0 Votes
    3 Posts
    997 Views
    T

    @doktornotor:

    Upgrade your pfSense.

    :) Yes just did fixed the issue
    Thanks

  • Snort 2.9.7.5 pkg v3.27 Update – Release Notes

    2
    0 Votes
    2 Posts
    681 Views
    F

    Thanks!  :D

  • Snort 2.9.7.5

    13
    0 Votes
    13 Posts
    3k Views
    bmeeksB

    @simby:

    Bmeeks, will be this in this release?

    It's not in the currently open Pull Request.

    Bill

  • Snort check for rule updates appearing as syslog errs, not info severity

    3
    0 Votes
    3 Posts
    815 Views
    F

    So limited API functionality in a way then.

    Ok thanks for letting me know, I'll add some exception rules for the monitoring system.  :)

  • Snort 3.2.6 supress lists changes made from block list not being saved

    14
    0 Votes
    14 Posts
    2k Views
    F

    https://www.defcon.org/images/defcon-19/dc-19-presentations/Duckwall/DEFCON-19-Duckwall-Bridge-Too-Far.pdf
    P115
    How can we defend this?

    Basically it’s a physical attack

    If somebody can plant a malicious device on your
    network you’re already screwed

    What has probably not crossed the authors mind is that an insecure network can be used to make a benign device a malicious device, by adding/altering some software. As I've already established there is nothing for vmware workstation to protect against arp poisoning as mentioned in a previous post, that is one area I am looking at amongst a few others, and virtualisation techniques have certainly come along a long way.

    So far logs for one of the device's are filling up nicely, caught some traffic which needs investigating, only 6 packets throughout the day out of several GB's but still got to get another device setup to do the packet capture with ssl bridging wanside.

    Learning iptables has been fun, I've never seen so many webpages making it seem complicated. I quite like iptables its quite easy once you figure it out at the command line.

  • Fw port scanning & snort blocks itself

    1
    0 Votes
    1 Posts
    716 Views
    No one has replied
  • Snort Passlist IPs still blocking

    7
    0 Votes
    7 Posts
    2k Views
    H

    Very strange!

    Yes, I setup passlist on interface. And restarted it.
    Yes, the IPs are on "Blocked" tab.

    But on 08/17 I edit the alias to ad some other IPs, restarted snort again, and voilá. Now it's working perfectly!!!

  • Snort Pass White List not working correctly?

    7
    0 Votes
    7 Posts
    3k Views
    H

    Hi

    I setup one passlist (only networks), set on interface, restart the interface.
    If I click on "view list" the IPs are there, but still blocking.
    I'm on 2.2.4 and Snort at 3.2.6
    Any Idea?
    Thanks.

  • Snort shows as not running in GUI, but process is

    8
    0 Votes
    8 Posts
    1k Views
    S

    @bmeeks:

    As for the GUI not showing Snort running, be aware that Snort can take a very, very long time to start.  Until it pretty much finishes the startup, it won't write the PID file that the GUI is looking for.  Until a matching PID file shows up, the GUI will display the Snort process on an interface as "not running".  Also, that screen is currently not "dynamic".  This means you need to refresh the screen periodically to see if Snort has started yet.  I have it on my to-do list to make that a dynamic screen in the future.

    Bill

    I wanted to confirm this is likely what is happening some of the time.  The start-up time after running filter updates appears to be about 10 minutes and I'm catching it during that time.  I know it was down for several days while I was away (at the start of this post).

    An "Updating" status in the GUI would be awesome (cause that's what GUIs are for)

    As often as we get poked and prodded, I'm not a fan of passing internet traffic without Snort taking a peek.

    Brian

  • Snort issue

    7
    0 Votes
    7 Posts
    2k Views
    ?

    Mine are Intel EXPI9400PTBLK NIC cards

    http://www.intel.com/content/www/us/en/network-adapters/gigabit-network-adapters/pro-1000-pt-server-adapter-brief.html

    Bought three of them for $9.99 each off ebay. All working awesome.

  • Snort Question

    9
    0 Votes
    9 Posts
    2k Views
    M

    i did some little research on snort but i might have missed it on custom rules.

    but i agree bmeeks :)

    @ fsansfil.
    Yes that is true the one that provided the list should have adjust it and he will do that. But the people that asked it in the first place provided wrong information about the way it works i guess so he didn't added it.

  • Snort analyze traffic before or after firewall rules?

    7
    0 Votes
    7 Posts
    2k Views
    C

    @bmeeks:

    @ckuecker:

    I dont have blocking enabled at the moment.  I plan on enabling it after some time once I get my rules massaged the way I want them.  Instead of using the auto-blocking feature of snort it would be nice to be able to manually add to the blocked list.

    I suppose that could be added, but the way blocking currently works anything added would be lost upon a reboot or complete restart of the packet filter.  This is because the pf table used for blocking (<snort2c>) is automatically cleared out by the packet filter upon a restart.  So blocks would not be persistent across reboots.

    Bill</snort2c>

    Interesting.. I didn't know that.  However, I rarely reboot so I think that would be acceptable.

  • Trouble with blocking through snort rules

    7
    0 Votes
    7 Posts
    3k Views
    bmeeksB

    @Vlee:

    Any other suggestions?

    No other suggestions.  I know alerting and blocking do work, so if you are not getting some specific alerts I suspect maybe the conditions needed to trigger the rules you have enabled are not happening in your environment.  Is your pfSense box set up rather conventionally meaning routable WAN IP (probably dynamic one from your ISP) and the LAN is using auto-NAT (the out-of-the-box configuration for pfSense).  You don't have something weird like bridging or some proxy arrangement do you?

    Bill

  • Suricata Starts then STOP - Crash

    16
    0 Votes
    16 Posts
    5k Views
    G

    I have since uninstalled it but have not been install it back. The installation never completes. I am able to install it via ssh though but not through the web console.

    Please see the attached. That is where it get stuck.

    Any ideas?

    suricata.png_thumb
    suricata.png

  • Limiting suricata logs

    5
    0 Votes
    5 Posts
    2k Views
    M

    I did reinstall the package, which upgraded it to version 2.1.6 and things are working fine now.

    Martin

  • Snort doing too much work? [RESOLVED]

    5
    0 Votes
    5 Posts
    1k Views
    C

    Thanks for all of the replies.  I was able to actually resolve this issue by moving Snort to a different interface.  I was already bridging my wan interface with an internal interface to be able to use my public IPs directly on my servers.  I moved Snort to the internal bridged interface instead of the external one (the wan) and left the firewall rules set up on the external interface.  The firewall on the external interface prevents any unwanted data from entering and ever making it to the internal interface.  Snort therefore no longer sees all of this garbage traffic.  I tested the whole setup by opening up the firewall on the external interface and watching all of the Snort alerts fly in.  As soon as I re-enabled the firewall, the alerts stopped.  My CPU load has been reduced by almost 75% as a result of this.  If you are using a similar setup, you may want to consider doing this as it seems to help quite a bit.

  • Barnyard2 exits if it can't connect to remote syslog

    3
    0 Votes
    3 Posts
    958 Views
    M

    Thanks Bill, much appreciated.

    I've switched it to UDP and added in further monitoring to ensure I get alerted when the logging stops for a period of time.

  • Suricata Deleting Blocklists on Reboot??

    5
    0 Votes
    5 Posts
    1k Views
    A

    Awesome!  Thank guys, that helps me understand a lot!

    @doktornotor yeah, I think it'd be nice upon reboot to maybe save the blocklist in /usr/pbi/suricata-amd64/local/etc/suricata/blocklists or something with a timestamp.  Then if you wanted to keep them it'd be as easy as creating a Alias URL table to point to that file.

  • Problem installing snort on pfSense 2.2.4

    6
    0 Votes
    6 Posts
    2k Views
    ivorI

    @ciph:

    @ivor:

    Is there a reason you're using i386 arch pfSense?

    No, not really, I dont remember why I choose it when I first installed pfSense (I have been running it for about 2 years now). Maybe it wasnt stable enough back then. But I have made a new installation with 64-bit version now. I know its recommended, thanks :)

    Nice !

  • Suricata/Snort Ruleset Management

    2
    0 Votes
    2 Posts
    2k Views
    bmeeksB

    Thanks for the suggestion and the links.  I will check this out.  It would not be too hard to add the ability to provide custom download URLs for additional rules.  The only gotcha is every rules file needs to be unique so the GUI can distinguish them.

    Bill

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.