Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Will snort turn itself off?

    Scheduled Pinned Locked Moved pfSense Packages
    8 Posts 3 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L Offline
      luciferactual
      last edited by

      Forgive me in advance:

      I'm new at this so.. I installed PFsense and updated it with 'Full-upgrade-1.2.2.', I installed (or added) snort via PFsense and everthing was running fine for a week. I check the PFsense every day before I do any heavy lifting on my machine, today I noticed snort was not running in services, is there any logical reason for this or should I be worried. I did have the box checked for updating snort once a week.

      I tried to review the snort logs nothing appeared as blocked, I looked at the firewall logs and from what I could tell it was just my machine connected to PFsense-my-mac-my i.p. I was spooked, so, what I did was restore to the most recent and complete back-up and changed my password. Now everything appears to be running again.

      My network is just my machine sitting behind PFsense. running version  1.2.2. I'm not quite sure how to retrieve and post logs at this point or I would have added what I thought to be relevant.

      thank you in advance

      Blue-Lou

      1 Reply Last reply Reply Quote 0
      • C Offline
        ColdFusion
        last edited by

        Snort has gone thru many changes the last week or two..It was just recently updated today. I would re-install snort.

        1 Reply Last reply Reply Quote 0
        • L Offline
          luciferactual
          last edited by

          Will do, thanks!

          1 Reply Last reply Reply Quote 0
          • L Offline
            luciferactual
            last edited by

            Ok…so I checked today and again snort was not running, (indicated by the red 'X') in the packages list. I did, however, find this entry:

            snort[12994]: FATAL ERROR: Dynamic detection lib /usr/local/lib/snort/dynamicrules//lib_sfdynamic_example_rule.so 1.0 isn't compatible with the current dynamic engine library /usr/local/lib/snort/dynamicengine/libsf_engine.so 1.10. The dynamic detection lib is compiled with an older version of the dynamic engine.

            Now from what I can understand here is that, again, I'm assuming is that the snort version I'm running is not compatible with my current pfsense build? Which is 1.2.2. with the updates added.  I have not reconfigured the system or made any changes at this point awaiting suggestions or advice.

            Thank you in advance.

            Lou.

            1 Reply Last reply Reply Quote 0
            • J Offline
              jamesdean
              last edited by

              @luciferactual:

              Ok…so I checked today and again snort was not running, (indicated by the red 'X') in the packages list. I did, however, find this entry:

              snort[12994]: FATAL ERROR: Dynamic detection lib /usr/local/lib/snort/dynamicrules//lib_sfdynamic_example_rule.so 1.0 isn't compatible with the current dynamic engine library /usr/local/lib/snort/dynamicengine/libsf_engine.so 1.10. The dynamic detection lib is compiled with an older version of the dynamic engine.

              Now from what I can understand here is that, again, I'm assuming is that the snort version I'm running is not compatible with my current pfsense build? Which is 1.2.2. with the updates added.  I have not reconfigured the system or made any changes at this point awaiting suggestions or advice.

              Thank you in advance.

              Lou.

              type this in the terminal

              "rm /usr/local/lib/snort/dynamicrules/lib_sfdynamic_example_rule.so"

              James

              1 Reply Last reply Reply Quote 0
              • L Offline
                luciferactual
                last edited by

                James,

                While waiting I tried a few things, I updated the firmware with the most current update (jan. 8th) and then I updated the snort rules. Snort said I was using older rules. Everything appeared to go smoothly. I restarted the machine and restarted snort. Everything seams to be working should I still add this line?

                "rm /usr/local/lib/snort/dynamicrules/lib_sfdynamic_example_rule.so"

                Thank you.

                Lou

                1 Reply Last reply Reply Quote 0
                • J Offline
                  jamesdean
                  last edited by

                  @luciferactual:

                  James,

                  While waiting I tried a few things, I updated the firmware with the most current update (jan. 8th) and then I updated the snort rules. Snort said I was using older rules. Everything appeared to go smoothly. I restarted the machine and restarted snort. Everything seams to be working should I still add this line?

                  "rm /usr/local/lib/snort/dynamicrules/lib_sfdynamic_example_rule.so"

                  Thank you.

                  Lou

                  No..

                  1 Reply Last reply Reply Quote 0
                  • L Offline
                    luciferactual
                    last edited by

                    James,

                    Copy that. I'll update you if need be.

                    Thanks

                    Lou.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.