Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort inilization failure

    Scheduled Pinned Locked Moved pfSense Packages
    100 Posts 8 Posters 53.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      ColdFusion
      last edited by

      It's funny I couldn't figure it either, I tried them all but acs worked consistently well. I'm using about 10% less ram also. The alerts are also triggering consistently better also. I'm running snort+squid, I wonder if all this is related to squid. Did anybody have this problem(core dumping) with just snort installed and not squid?

      1 Reply Last reply Reply Quote 0
      • P
        PC_Arcade
        last edited by

        Yep, me. I've only been running SNORT.

        Although I will add Squid as soon as it becomes available again.

        acs uses significantly less memory for me too and also works as intended. Thank coldfusion

        1 Reply Last reply Reply Quote 0
        • S
          sullrich
          last edited by

          @yoda715:

          Question is, why?

          No idea.  This is now a SNORT issue and this should be asked on their lists.

          1 Reply Last reply Reply Quote 0
          • P
            PC_Arcade
            last edited by

            I think the latest version of SNORT (2.6.1.1) fixes this issue

            1 Reply Last reply Reply Quote 0
            • Y
              yoda715
              last edited by

              Not sure if this fixes our issue.

              This is the issue solved in 2.6.1.1: "Fix problem with snort using high CPU and reprocessing the same rebuilt packets at session end or ACK in middle of packet when there are gaps in the packet sequence."

              1 Reply Last reply Reply Quote 0
              • P
                PC_Arcade
                last edited by

                certainly seems to :)

                Running in sparsebands now, only been up for ~5 minutes, but that's ~3 more than I've managed before

                1 Reply Last reply Reply Quote 0
                • Y
                  yoda715
                  last edited by

                  I updated to the 2.6.1.1 versions and now I cant even get Snort to boot up on any performance setting. I am getting brand new errors now:

                  Nov 24 14:53:39 snort2c[1571]: unable to open alertfile - exit
                  Nov 24 14:53:39 snort2c[1571]: unable to open alertfile - exit
                  Nov 24 14:53:39 snort2c[1571]: snort2c running in daemon mode pid: 1571
                  Nov 24 14:53:39 snort2c[1571]: snort2c running in daemon mode pid: 1571

                  I am running the 1.0.1-SNAPSHOT-11-24-2006

                  1 Reply Last reply Reply Quote 0
                  • S
                    sullrich
                    last edited by

                    Oh bugger.  I'll check it out a bit later tonite.

                    1 Reply Last reply Reply Quote 0
                    • Y
                      yoda715
                      last edited by

                      Thanks Scott.

                      1 Reply Last reply Reply Quote 0
                      • P
                        PC_Arcade
                        last edited by

                        Didn't do that for me, BUT it also didn't trigger any alerts

                        1 Reply Last reply Reply Quote 0
                        • Y
                          yoda715
                          last edited by

                          Try running a port scan from http://www.grc.com. You should see it appear in alert as a ping.

                          1 Reply Last reply Reply Quote 0
                          • C
                            ColdFusion
                            last edited by

                            I'm pretty much screwed with the same alert after I upgraded SNORT. Now the service will not start and stay running.

                            1 Reply Last reply Reply Quote 0
                            • Y
                              yoda715
                              last edited by

                              Scott, I see where you reverted snort back to the 2.6.0.2.5. I reverted back to that version and I'm still getting the same error. The trouble must be in the latest snapshot.

                              1 Reply Last reply Reply Quote 0
                              • P
                                PC_Arcade
                                last edited by

                                @yoda715:

                                Try running a port scan from http://www.grc.com. You should see it appear in alert as a ping.

                                I know, and it doesn't.

                                I've reverted back to the older version and it still doesn't raise any alerts at all  ???

                                1 Reply Last reply Reply Quote 0
                                • Y
                                  yoda715
                                  last edited by

                                  What snapshot are you running? I'm thinking it has something to do with that since I too reverted back to the older version of snort.

                                  1 Reply Last reply Reply Quote 0
                                  • C
                                    ColdFusion
                                    last edited by

                                    Version 1.01

                                    1 Reply Last reply Reply Quote 0
                                    • P
                                      PC_Arcade
                                      last edited by

                                      @yoda715:

                                      What snapshot are you running? I'm thinking it has something to do with that since I too reverted back to the older version of snort.

                                      1.0.1-SNAPSHOT-11-19-2006

                                      1 Reply Last reply Reply Quote 0
                                      • C
                                        ColdFusion
                                        last edited by

                                        Well, it boiled down to me just re-installing pfSense(1.01) and re-installing SNORT. It started fine. I kept getting could not open alert file…..no matter what I did.......but now (keeping my fingers crossed) everything looks good.

                                        1 Reply Last reply Reply Quote 0
                                        • P
                                          PC_Arcade
                                          last edited by

                                          I think I'd rather do without snort than re-install from scratch

                                          1 Reply Last reply Reply Quote 0
                                          • S
                                            sullrich
                                            last edited by

                                            Backup your configuration, reinstall, restore configuration.

                                            It takes about 6 minutes on a 800 mhz machine.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.