Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    snort running to half stop many times a day

    Scheduled Pinned Locked Moved IDS/IPS
    23 Posts 6 Posters 2.8k Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      blackkep @bmeeks
      last edited by blackkep

      @bmeeks @jonathanlee
      thank you solved it

      P 1 Reply Last reply Reply Quote 0
      • P Offline
        Patch @blackkep
        last edited by

        @blackkep said in snort running to half stop many times a day:

        thank you solved it

        Out of interest what change actually fixed it

        B 1 Reply Last reply Reply Quote 0
        • B Offline
          blackkep @Patch
          last edited by

          @patch
          There is a rule to turn off snort can be normal

          Might have to wait until the next update to enable this rule

          fireodoF 1 Reply Last reply Reply Quote 0
          • fireodoF Online
            fireodo @blackkep
            last edited by

            @blackkep said in snort running to half stop many times a day:

            There is a rule to turn off snort can be normal

            And wich one? Can you tell us too?

            Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
            SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
            pfsense 2.8.0 CE
            Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

            B 1 Reply Last reply Reply Quote 0
            • B Offline
              blackkep @fireodo
              last edited by

              @fireodo After you update the rules also ?

              emerging-drop.rules

              fireodoF S 2 Replies Last reply Reply Quote 0
              • fireodoF Online
                fireodo @blackkep
                last edited by fireodo

                @blackkep said in snort running to half stop many times a day:

                @fireodo After you update the rules also ?

                From time to time Snort exits on rules update (here) with signal 11 but it will continuing running normal.

                emerging-drop.rules

                Thanks. (not enabled here)

                Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                pfsense 2.8.0 CE
                Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                B 1 Reply Last reply Reply Quote 0
                • B Offline
                  blackkep @fireodo
                  last edited by blackkep

                  @fireodo This bug has been around for a long time

                  1 Reply Last reply Reply Quote 1
                  • S Offline
                    SteveITS Rebel Alliance @blackkep
                    last edited by

                    @blackkep If you want an alternative for DROP, you can use pfBlocker and pick DROP from its feed list. Then create a regular firewall block rule via the feed set as Alias Native, or have it create the rule via Deny.

                    Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                    Upvote 👍 helpful posts!

                    B 2 Replies Last reply Reply Quote 2
                    • B Offline
                      blackkep @SteveITS
                      last edited by

                      @steveits 33228368-d56c-4be4-bafa-858990955986-image.png The DROP rule is still running ?

                      S 1 Reply Last reply Reply Quote 0
                      • B Offline
                        blackkep @SteveITS
                        last edited by

                        @steveits pfblockerng DROP I see the original list

                        1 Reply Last reply Reply Quote 0
                        • S Offline
                          SteveITS Rebel Alliance @blackkep
                          last edited by

                          @blackkep said in snort running to half stop many times a day:

                          @steveits The DROP rule is still running ?

                          Not sure I understand the question…if you are using pfBlocker you can disable the category in Snort. No need to scan twice.

                          Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                          When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                          Upvote 👍 helpful posts!

                          B 1 Reply Last reply Reply Quote 0
                          • B Offline
                            blackkep @SteveITS
                            last edited by

                            @steveits It is very strange that snort has canceled the DROP rule and is still running

                            S 1 Reply Last reply Reply Quote 0
                            • S Offline
                              SteveITS Rebel Alliance @blackkep
                              last edited by

                              @blackkep Did you restart Snort in that interface to pick up the new settings? Check if multiple Snort processes are running and if so end them or restart your router.

                              Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                              When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                              Upvote 👍 helpful posts!

                              B 1 Reply Last reply Reply Quote 0
                              • B Offline
                                blackkep @SteveITS
                                last edited by

                                @steveits
                                snort restarted , snort has only one

                                S 1 Reply Last reply Reply Quote 0
                                • S Offline
                                  SteveITS Rebel Alliance @blackkep
                                  last edited by

                                  @blackkep And did you restart your router?

                                  Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                  When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                                  Upvote 👍 helpful posts!

                                  B 1 Reply Last reply Reply Quote 0
                                  • B Offline
                                    blackkep @SteveITS
                                    last edited by

                                    @steveits pfsense restart

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.