Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort 2.8.4.1 pkg v. 1.5 Categories Disable Rules after update

    Scheduled Pinned Locked Moved pfSense Packages
    5 Posts 3 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      Davc
      last edited by

      Does anyone has the same experience on Snort 2.8.4.1 pkg v. 1.5 in disabling Rules?

      As I am not very good in explaining such cases, so these are my steps:

      For example:
      I go to Snort "Catergories" and select "emergency-scan.rules" then disable one of the rule (SID "2002992" ET SCAN Rapid POP3 Connections - Possible Brute Force Attack) and click "Apply Changes".

      Then run an "Update Rules" and go back to this "emergency-scan.rules" interface, this "SID" rules I last disabled has become activated again.

      Isn't it supposed to stay as disabled?

      DavC

      1 Reply Last reply Reply Quote 0
      • J Offline
        jamesdean
        last edited by

        DavC

        Yes, every time you make rule changes they are reset if you do a rule update.

        I working on a solution right now. This is very important to me to.
        I want to have this fixed in the next 2 days.

        James

        1 Reply Last reply Reply Quote 0
        • D Offline
          Davc
          last edited by

          James,

          Many thanks for looking after this issue.

          Look forward to hearing the good news from you.

          Best Regards,

          DavC

          1 Reply Last reply Reply Quote 0
          • R Offline
            Roodawakening
            last edited by

            James…

            I'm still seeing double error notifications. Any idea why?

            "The descent to hell is easy. The gates stand open day and night. But to reclimb the slope and escape to the upper air: This is labor."
            –Virgil, Aeneid, Book 6

            Rob

            1 Reply Last reply Reply Quote 0
            • J Offline
              jamesdean
              last edited by

              There not error messages just snort statistics and general info.
              Im going to disable logging to system logs on start-up by editing the snort source code.

              James

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.