Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SNORT gone after Pfsense update

    Scheduled Pinned Locked Moved IDS/IPS
    23 Posts 3 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SteveITS Galactic Empire @SteveITS
      last edited by

      @steveits said in SNORT gone after Pfsense update:

      hope "previous stable version" doesn't become 2.5.0...

      2.5.1 is out, looks like "previous" is still 2.4.5, and "latest" is "2.5.x."

      No mention in the release notes about PHP on SG-3100 being a known issue but the Redmine issue is still open.

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote πŸ‘ helpful posts!

      M 1 Reply Last reply Reply Quote 0
      • M
        mikej47 @SteveITS
        last edited by

        @steveits Thanks for the update. I was able to obtain the older version from Netgate and recovered last night and am now back on 2.4.5.

        I checked the release notes before upgrading to 2.5.x to be safe and of course this wasn't in it then.

        This makes me hesitant to upgrade to any new version :(

        S 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @mikej47
          last edited by

          Yeah...in general I try to observe a vendor forum for a while before jumping in, especially on a ".0" release. As helpful as beta testers are, "the world" will always find more bugs. And yes I know this is 2.5.0 but there were six versions of 2.4.x before that (0-5). All I can say is over the last 10 years or so pfSense releases have been pretty good. I don't really recall any long term issues as they are pretty good about "p1" patches.

          My "bystander" guess is that since the SG-3100 issues seem to appear with packages then it's not a core pfSense flaw and thus wasn't found in 2.5.0 testing...however since it's apparently a PHP issue then it is going to take a PHP and then pfSense update to fix it.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote πŸ‘ helpful posts!

          M 1 Reply Last reply Reply Quote 1
          • M
            mikej47 @SteveITS
            last edited by

            @steveits Hi, have you been able to find any updates on this. I keep checking the bug tracking system but haven't seen anything in a long time. Not sure if it is normal for it to take this long.

            S 1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @mikej47
              last edited by

              Netgate's pretty quick on bugs in pfSense code. I expect since it's not a pfSense bug the only option is to wait until Zend/PHP fixes it. I would plan to not upgrade for a while.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote πŸ‘ helpful posts!

              M 1 Reply Last reply Reply Quote 0
              • M
                mikej47 @SteveITS
                last edited by

                @steveits Makes sense. Thank you for the info!

                1 Reply Last reply Reply Quote 0
                • bmeeksB
                  bmeeks
                  last edited by bmeeks

                  For users having issues with Snort or Suricata installing on Netgate SG-3100 appliances, try the patch provided by @jimp in this thread: https://forum.netgate.com/topic/161050/snort-won-t-start-after-upgrade-to-21-02-on-sg-3100/24?_=1622736263256.

                  The patch makes a change to a PHP configuration value, but you will need to follow the instructions in the post to make sure the PHP engine loads the new value.

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    mikej47 @bmeeks
                    last edited by

                    @bmeeks Has anyone had any luck with this patch? Does it fix Pfblocker as well as snort?

                    bmeeksB 1 Reply Last reply Reply Quote 0
                    • bmeeksB
                      bmeeks @mikej47
                      last edited by bmeeks

                      @mikej47 said in SNORT gone after Pfsense update:

                      @bmeeks Has anyone had any luck with this patch? Does it fix Pfblocker as well as snort?

                      The PHP patch has been reported, by multiple users, to fix the issues with PHP crashing for both packages. The crash of PHP itself is the cause of the failure to complete installation for the Snort package.

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        mikej47 @bmeeks
                        last edited by

                        @bmeeks Thank you for the information.

                        This will be my first time installing a patch on in Pfsense. I plan on following the procedure found at https://docs.netgate.com/pfsense/en/latest/development/system-patches.html - "System Patches Package".

                        My SG-3100 is currently running 2.4.5-RELEASE-p1.

                        Do I first upgrade Pfsense by going to System > Update > and for Branch selecting Latest stable version 21.02.x , upgrading Pfsense, and then install the patch?

                        Thank you.

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          SteveITS Galactic Empire @mikej47
                          last edited by

                          @mikej47 said in SNORT gone after Pfsense update:

                          Do I first upgrade Pfsense by going to System > Update > and for Branch selecting Latest stable version 21.02.x , upgrading Pfsense, and then install the patch?

                          Yes but if it’s only showing you 21.02 not 21.05 you may need to update twice. Without looking, I’m pretty sure the patch was for 21.05.

                          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                          Upvote πŸ‘ helpful posts!

                          1 Reply Last reply Reply Quote 0
                          • bmeeksB
                            bmeeks
                            last edited by bmeeks

                            The PHP patch is in the 21.05.1 release of pfSense+. Here is a link to the Release Notes: https://docs.netgate.com/pfsense/en/latest/releases/21-05-1.html.

                            So if you update to that version of pfSense+, you will not need to install the patch -- it's already baked in.

                            M 1 Reply Last reply Reply Quote 2
                            • M
                              mikej47 @bmeeks
                              last edited by

                              @bmeeks that is great news. I can just upgrade to that version and the patch is built in. What is Pfsense + ? How do I get the + version?

                              bmeeksB 1 Reply Last reply Reply Quote 0
                              • bmeeksB
                                bmeeks @mikej47
                                last edited by

                                @mikej47 said in SNORT gone after Pfsense update:

                                @bmeeks that is great news. I can just upgrade to that version and the patch is built in. What is Pfsense + ? How do I get the + version?

                                pfSense+ is the new name for the old "Factory Edition" of pfSense that comes on Netgate appliances. When you upgrade to the latest 21.05.1 version, pfSense+ is what that will be.

                                1 Reply Last reply Reply Quote 1
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.