Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SNORT gone after Pfsense update

    Scheduled Pinned Locked Moved IDS/IPS
    23 Posts 3 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mikej47 @SteveITS
      last edited by

      @steveits Thanks for the update. I was able to obtain the older version from Netgate and recovered last night and am now back on 2.4.5.

      I checked the release notes before upgrading to 2.5.x to be safe and of course this wasn't in it then.

      This makes me hesitant to upgrade to any new version :(

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @mikej47
        last edited by

        Yeah...in general I try to observe a vendor forum for a while before jumping in, especially on a ".0" release. As helpful as beta testers are, "the world" will always find more bugs. And yes I know this is 2.5.0 but there were six versions of 2.4.x before that (0-5). All I can say is over the last 10 years or so pfSense releases have been pretty good. I don't really recall any long term issues as they are pretty good about "p1" patches.

        My "bystander" guess is that since the SG-3100 issues seem to appear with packages then it's not a core pfSense flaw and thus wasn't found in 2.5.0 testing...however since it's apparently a PHP issue then it is going to take a PHP and then pfSense update to fix it.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote πŸ‘ helpful posts!

        M 1 Reply Last reply Reply Quote 1
        • M
          mikej47 @SteveITS
          last edited by

          @steveits Hi, have you been able to find any updates on this. I keep checking the bug tracking system but haven't seen anything in a long time. Not sure if it is normal for it to take this long.

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @mikej47
            last edited by

            Netgate's pretty quick on bugs in pfSense code. I expect since it's not a pfSense bug the only option is to wait until Zend/PHP fixes it. I would plan to not upgrade for a while.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote πŸ‘ helpful posts!

            M 1 Reply Last reply Reply Quote 0
            • M
              mikej47 @SteveITS
              last edited by

              @steveits Makes sense. Thank you for the info!

              1 Reply Last reply Reply Quote 0
              • bmeeksB
                bmeeks
                last edited by bmeeks

                For users having issues with Snort or Suricata installing on Netgate SG-3100 appliances, try the patch provided by @jimp in this thread: https://forum.netgate.com/topic/161050/snort-won-t-start-after-upgrade-to-21-02-on-sg-3100/24?_=1622736263256.

                The patch makes a change to a PHP configuration value, but you will need to follow the instructions in the post to make sure the PHP engine loads the new value.

                M 1 Reply Last reply Reply Quote 0
                • M
                  mikej47 @bmeeks
                  last edited by

                  @bmeeks Has anyone had any luck with this patch? Does it fix Pfblocker as well as snort?

                  bmeeksB 1 Reply Last reply Reply Quote 0
                  • bmeeksB
                    bmeeks @mikej47
                    last edited by bmeeks

                    @mikej47 said in SNORT gone after Pfsense update:

                    @bmeeks Has anyone had any luck with this patch? Does it fix Pfblocker as well as snort?

                    The PHP patch has been reported, by multiple users, to fix the issues with PHP crashing for both packages. The crash of PHP itself is the cause of the failure to complete installation for the Snort package.

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      mikej47 @bmeeks
                      last edited by

                      @bmeeks Thank you for the information.

                      This will be my first time installing a patch on in Pfsense. I plan on following the procedure found at https://docs.netgate.com/pfsense/en/latest/development/system-patches.html - "System Patches Package".

                      My SG-3100 is currently running 2.4.5-RELEASE-p1.

                      Do I first upgrade Pfsense by going to System > Update > and for Branch selecting Latest stable version 21.02.x , upgrading Pfsense, and then install the patch?

                      Thank you.

                      S 1 Reply Last reply Reply Quote 0
                      • S
                        SteveITS Galactic Empire @mikej47
                        last edited by

                        @mikej47 said in SNORT gone after Pfsense update:

                        Do I first upgrade Pfsense by going to System > Update > and for Branch selecting Latest stable version 21.02.x , upgrading Pfsense, and then install the patch?

                        Yes but if it’s only showing you 21.02 not 21.05 you may need to update twice. Without looking, I’m pretty sure the patch was for 21.05.

                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                        Upvote πŸ‘ helpful posts!

                        1 Reply Last reply Reply Quote 0
                        • bmeeksB
                          bmeeks
                          last edited by bmeeks

                          The PHP patch is in the 21.05.1 release of pfSense+. Here is a link to the Release Notes: https://docs.netgate.com/pfsense/en/latest/releases/21-05-1.html.

                          So if you update to that version of pfSense+, you will not need to install the patch -- it's already baked in.

                          M 1 Reply Last reply Reply Quote 2
                          • M
                            mikej47 @bmeeks
                            last edited by

                            @bmeeks that is great news. I can just upgrade to that version and the patch is built in. What is Pfsense + ? How do I get the + version?

                            bmeeksB 1 Reply Last reply Reply Quote 0
                            • bmeeksB
                              bmeeks @mikej47
                              last edited by

                              @mikej47 said in SNORT gone after Pfsense update:

                              @bmeeks that is great news. I can just upgrade to that version and the patch is built in. What is Pfsense + ? How do I get the + version?

                              pfSense+ is the new name for the old "Factory Edition" of pfSense that comes on Netgate appliances. When you upgrade to the latest 21.05.1 version, pfSense+ is what that will be.

                              1 Reply Last reply Reply Quote 1
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.