Snort uninstalling itself pfsense 1.2.3
-
I did a fresh install of the 1.2.3 release. I installed snort and configured it. Everything is fine for about 1 hour. Suddently my connection drops. Upon login it immediate brings me to the system->packages->remove_packages menu and snorts start to uninstall. After reinstalling snort, I thought it was some sort of glitch. On the off chance it wasn't I decided to reinstall the 1.2.3 release while saving the configuration.
This morning, I reinstalled pfsense and restored the configuration. I installed snort and configured it. I clicked the system menu again and once more it brings me to the uninstall package page with snort being removed. The fact that it happened a 2nd time makes me believe that it was a bug of some sort. I'm looking for anyone who has encountered the same problem.
-
My snort package is snort 2.8.4.1_5 pkg v.1.7
-
That is not good. I have not touched the snort 2.8.4.1_5 pkg v.1.7 in months.
Hold on I'll check, I feel today is going to suck for me.
Post so logs if you have them please.
James
My snort package is snort 2.8.4.1_5 pkg v.1.7
-
Sorry, I don't have any logs when it disconnected. I reinstalled snort right after and when I finally thought, "hey maybe I should save the logs" snort booted up and removed whatever logs were available. (still haven't figured out how to set up a remote syslog server yet with debian)
I'll be sure to keep the logs if or when it happens again.
The fact that you haven't touched that package suggests to me that it isn't current. Is there another way to get snort other than whats listed in the packages pfsense gui?
-
You could compile snort for yourself, but you will lose the IPS part.
Im testing the old snort package and every thing seems fine.
James
Sorry, I don't have any logs when it disconnected. I reinstalled snort right after and when I finally thought, "hey maybe I should save the logs" snort booted up and removed whatever logs were available. (still haven't figured out how to set up a remote syslog server yet with debian)
I'll be sure to keep the logs if or when it happens again.
The fact that you haven't touched that package suggests to me that it isn't current. Is there another way to get snort other than whats listed in the packages pfsense gui?
-
It happened again. Right after I installed DNS blacklist I went to the system menu to look at memory usage and it brought me to the install packages menu. Basically it uninstalled and then reinstalled DNS blacklist and Snort. So here are the logs from the period of the DNS blacklist install to the reinstallation of snort.
Dec 18 11:27:06 php: /pkg_mgr_install.php: Beginning package installation for DNS Blacklist.
Dec 18 11:27:05 php: /pkg_mgr_install.php: cd /var/db/pkg && pkg_delete ls | grep
Dec 18 11:27:05 php: /pkg_mgr_install.php: cd /var/db/pkg && pkg_delete ls | grep DNS Blacklist-0.2.4
Dec 18 11:27:05 php: /pkg_mgr_install.php: XML error: not well-formed (invalid token) at line 1
Dec 18 11:26:04 php: /pkg_mgr_install.php: Beginning package installation for snort.
Dec 18 11:25:59 snort[9630]: Snort exiting
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: Snort exiting
Dec 18 11:25:59 snort[9630]:Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: Total sessions: 0
Dec 18 11:25:59 snort[9630]: Total sessions: 0
Dec 18 11:25:59 snort[9630]: dcerpc2 Preprocessor Statistics
Dec 18 11:25:59 snort[9630]: dcerpc2 Preprocessor Statistics
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: Total packets processed: 4505
Dec 18 11:25:59 snort[9630]: Total packets processed: 4505
Dec 18 11:25:59 snort[9630]: Self-referencing paths ("./"): 0
Dec 18 11:25:59 snort[9630]: Self-referencing paths ("./"): 0
Dec 18 11:25:59 snort[9630]: Extra slashes ("//"): 0
Dec 18 11:25:59 snort[9630]: Extra slashes ("//"): 0
Dec 18 11:25:59 snort[9630]: Directory traversals: 0
Dec 18 11:25:59 snort[9630]: Directory traversals: 0
Dec 18 11:25:59 snort[9630]: Base 36: 0
Dec 18 11:25:59 snort[9630]: Base 36: 0
Dec 18 11:25:59 snort[9630]: Non-ASCII representable: 0
Dec 18 11:25:59 snort[9630]: Non-ASCII representable: 0
Dec 18 11:25:59 snort[9630]: Double unicode: 0
Dec 18 11:25:59 snort[9630]: Double unicode: 0
Dec 18 11:25:59 snort[9630]: Unicode: 0
Dec 18 11:25:59 snort[9630]: Unicode: 0
Dec 18 11:25:59 snort[9630]: Post parameters extracted: 0
Dec 18 11:25:59 snort[9630]: Post parameters extracted: 0
Dec 18 11:25:59 snort[9630]: Header Cookies extracted: 0
Dec 18 11:25:59 snort[9630]: Header Cookies extracted: 0
Dec 18 11:25:59 snort[9630]: Headers extracted: 18
Dec 18 11:25:59 snort[9630]: Headers extracted: 18
Dec 18 11:25:59 snort[9630]: GET methods: 10
Dec 18 11:25:59 snort[9630]: GET methods: 10
Dec 18 11:25:59 snort[9630]: POST methods: 8
Dec 18 11:25:59 snort[9630]: POST methods: 8
Dec 18 11:25:59 snort[9630]: HTTP Inspect - encodings (Note: stream-reassembled packets included):
Dec 18 11:25:59 snort[9630]: HTTP Inspect - encodings (Note: stream-reassembled packets included):
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: Tracked: 44
Dec 18 11:25:59 snort[9630]: Tracked: 44
Dec 18 11:25:59 snort[9630]: Inspected: 0
Dec 18 11:25:59 snort[9630]: Inspected: 0
Dec 18 11:25:59 snort[9630]: Dropped: 0
Dec 18 11:25:59 snort[9630]: Dropped: 0
Dec 18 11:25:59 snort[9630]: UDP Port Filter
Dec 18 11:25:59 snort[9630]: UDP Port Filter
Dec 18 11:25:59 snort[9630]: Tracked: 9255
Dec 18 11:25:59 snort[9630]: Tracked: 9255
Dec 18 11:25:59 snort[9630]: Inspected: 0
Dec 18 11:25:59 snort[9630]: Inspected: 0
Dec 18 11:25:59 snort[9630]: Dropped: 0
Dec 18 11:25:59 snort[9630]: Dropped: 0
Dec 18 11:25:59 snort[9630]: TCP Port Filter
Dec 18 11:25:59 snort[9630]: TCP Port Filter
Dec 18 11:25:59 snort[9630]: Events: 0
Dec 18 11:25:59 snort[9630]: Events: 0
Dec 18 11:25:59 snort[9630]: UDP Discards: 0
Dec 18 11:25:59 snort[9630]: UDP Discards: 0
Dec 18 11:25:59 snort[9630]: UDP Timeouts: 6
Dec 18 11:25:59 snort[9630]: UDP Timeouts: 6
Dec 18 11:25:59 snort[9630]: UDP Sessions Deleted: 22
Dec 18 11:25:59 snort[9630]: UDP Sessions Deleted: 22
Dec 18 11:25:59 snort[9630]: UDP Sessions Created: 22
Dec 18 11:25:59 snort[9630]: UDP Sessions Created: 22
Dec 18 11:25:59 snort[9630]: TCP Discards: 9
Dec 18 11:25:59 snort[9630]: TCP Discards: 9
Dec 18 11:25:59 snort[9630]: TCP Segments Used: 9
Dec 18 11:25:59 snort[9630]: TCP Segments Used: 9
Dec 18 11:25:59 snort[9630]: TCP Rebuilt Packets: 9
Dec 18 11:25:59 snort[9630]: TCP Rebuilt Packets: 9
Dec 18 11:25:59 snort[9630]: TCP Segments Released: 9
Dec 18 11:25:59 snort[9630]: TCP Segments Released: 9
Dec 18 11:25:59 snort[9630]: TCP Segments Queued: 9
Dec 18 11:25:59 snort[9630]: TCP Segments Queued: 9
Dec 18 11:25:59 snort[9630]: TCP Overlaps: 0
Dec 18 11:25:59 snort[9630]: TCP Overlaps: 0
Dec 18 11:25:59 snort[9630]: TCP Timeouts: 0
Dec 18 11:25:59 snort[9630]: TCP Timeouts: 0
Dec 18 11:25:59 snort[9630]: TCP StreamTrackers Deleted: 9
Dec 18 11:25:59 snort[9630]: TCP StreamTrackers Deleted: 9
Dec 18 11:25:59 snort[9630]: TCP StreamTrackers Created: 9
Dec 18 11:25:59 snort[9630]: TCP StreamTrackers Created: 9
Dec 18 11:25:59 snort[9630]: ICMP Prunes: 0
Dec 18 11:25:59 snort[9630]: ICMP Prunes: 0
Dec 18 11:25:59 snort[9630]: UDP Prunes: 0
Dec 18 11:25:59 snort[9630]: UDP Prunes: 0
Dec 18 11:25:59 snort[9630]: TCP Prunes: 0
Dec 18 11:25:59 snort[9630]: TCP Prunes: 0
Dec 18 11:25:59 snort[9630]: ICMP sessions: 0
Dec 18 11:25:59 snort[9630]: ICMP sessions: 0
Dec 18 11:25:59 snort[9630]: UDP sessions: 16
Dec 18 11:25:59 snort[9630]: UDP sessions: 16
Dec 18 11:25:59 snort[9630]: TCP sessions: 9
Dec 18 11:25:59 snort[9630]: TCP sessions: 9
Dec 18 11:25:59 snort[9630]: Total sessions: 25
Dec 18 11:25:59 snort[9630]: Total sessions: 25
Dec 18 11:25:59 snort[9630]: Stream5 statistics:
Dec 18 11:25:59 snort[9630]: Stream5 statistics:
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: Frag Nodes Deleted: 0
Dec 18 11:25:59 snort[9630]: Frag Nodes Deleted: 0
Dec 18 11:25:59 snort[9630]: Frag Nodes Inserted: 0
Dec 18 11:25:59 snort[9630]: Frag Nodes Inserted: 0
Dec 18 11:25:59 snort[9630]: FragTrackers Auto Freed: 0
Dec 18 11:25:59 snort[9630]: FragTrackers Auto Freed: 0
Dec 18 11:25:59 snort[9630]: FragTrackers Dumped: 0
Dec 18 11:25:59 snort[9630]: FragTrackers Dumped: 0
Dec 18 11:25:59 snort[9630]: FragTrackers Added: 0
Dec 18 11:25:59 snort[9630]: FragTrackers Added: 0
Dec 18 11:25:59 snort[9630]: Alerts: 0
Dec 18 11:25:59 snort[9630]: Alerts: 0
Dec 18 11:25:59 snort[9630]: Anomalies: 0
Dec 18 11:25:59 snort[9630]: Anomalies: 0
Dec 18 11:25:59 snort[9630]: Overlaps: 0
Dec 18 11:25:59 snort[9630]: Overlaps: 0
Dec 18 11:25:59 snort[9630]: Timeouts: 0
Dec 18 11:25:59 snort[9630]: Timeouts: 0
Dec 18 11:25:59 snort[9630]: Memory Faults: 0
Dec 18 11:25:59 snort[9630]: Memory Faults: 0
Dec 18 11:25:59 snort[9630]: Discards: 0
Dec 18 11:25:59 snort[9630]: Discards: 0
Dec 18 11:25:59 snort[9630]: Frags Reassembled: 0
Dec 18 11:25:59 snort[9630]: Frags Reassembled: 0
Dec 18 11:25:59 snort[9630]: Total Fragments: 0
Dec 18 11:25:59 snort[9630]: Total Fragments: 0
Dec 18 11:25:59 snort[9630]: Frag3 statistics:
Dec 18 11:25:59 snort[9630]: Frag3 statistics:
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: mpse: queue uinserts = 73829
Dec 18 11:25:59 snort[9630]: mpse: queue uinserts = 73829
Dec 18 11:25:59 snort[9630]: mpse: queue inserts = 342115
Dec 18 11:25:59 snort[9630]: mpse: queue inserts = 342115
Dec 18 11:25:59 snort[9630]: mpse: queue flushes = 34
Dec 18 11:25:59 snort[9630]: mpse: queue flushes = 34
Dec 18 11:25:59 snort[9630]: mpse: queue size = 32, max possible = 32
Dec 18 11:25:59 snort[9630]: mpse: queue size = 32, max possible = 32
Dec 18 11:25:59 snort[9630]: ac-bnfa: queue uinserts = 73829
Dec 18 11:25:59 snort[9630]: ac-bnfa: queue uinserts = 73829
Dec 18 11:25:59 snort[9630]: ac-bnfa: queue inserts = 342115
Dec 18 11:25:59 snort[9630]: ac-bnfa: queue inserts = 342115
Dec 18 11:25:59 snort[9630]: ac-bnfa: queue flushes = 34
Dec 18 11:25:59 snort[9630]: ac-bnfa: queue flushes = 34
Dec 18 11:25:59 snort[9630]: ac-bnfa: queue size = 32, max = 32
Dec 18 11:25:59 snort[9630]: ac-bnfa: queue size = 32, max = 32
Dec 18 11:25:59 snort[9630]: lowmem: queue uinserts = 73829
Dec 18 11:25:59 snort[9630]: lowmem: queue uinserts = 73829
Dec 18 11:25:59 snort[9630]: lowmem: queue inserts = 342115
Dec 18 11:25:59 snort[9630]: lowmem: queue inserts = 342115
Dec 18 11:25:59 snort[9630]: lowmem: queue flushes = 34
Dec 18 11:25:59 snort[9630]: lowmem: queue flushes = 34
Dec 18 11:25:59 snort[9630]: lowmem: queue size = 32, max = 32
Dec 18 11:25:59 snort[9630]: lowmem: queue size = 32, max = 32
Dec 18 11:25:59 snort[9630]: PASSED: 0
Dec 18 11:25:59 snort[9630]: PASSED: 0
Dec 18 11:25:59 snort[9630]: LOGGED: 0
Dec 18 11:25:59 snort[9630]: LOGGED: 0
Dec 18 11:25:59 snort[9630]: ALERTS: 0
Dec 18 11:25:59 snort[9630]: ALERTS: 0
Dec 18 11:25:59 snort[9630]: Action Stats:
Dec 18 11:25:59 snort[9630]: Action Stats:
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: Total: 16190
Dec 18 11:25:59 snort[9630]: Total: 16190
Dec 18 11:25:59 snort[9630]: S5 G 2: 9 (0.056%)
Dec 18 11:25:59 snort[9630]: S5 G 2: 9 (0.056%)
Dec 18 11:25:59 snort[9630]: S5 G 1: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: S5 G 1: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: InvChkSum: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: InvChkSum: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: DISCARD: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: DISCARD: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: OTHER: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: OTHER: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IPX: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IPX: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ETHLOOP: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ETHLOOP: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: EAPOL: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: EAPOL: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ARP: 6732 (41.581%)
Dec 18 11:25:59 snort[9630]: ARP: 6732 (41.581%)
Dec 18 11:25:59 snort[9630]: FRAG 6: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: FRAG 6: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: FRAG: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: FRAG: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ICMPdis: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ICMPdis: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: UDPdisc: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: UDPdisc: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: TCPdisc: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: TCPdisc: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ICMP: 150 (0.926%)
Dec 18 11:25:59 snort[9630]: ICMP: 150 (0.926%)
Dec 18 11:25:59 snort[9630]: UDP: 44 (0.272%)
Dec 18 11:25:59 snort[9630]: UDP: 44 (0.272%)
Dec 18 11:25:59 snort[9630]: TCP: 9264 (57.221%)
Dec 18 11:25:59 snort[9630]: TCP: 9264 (57.221%)
Dec 18 11:25:59 snort[9630]: ICMP-IP: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ICMP-IP: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ICMP6: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ICMP6: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: UDP 6: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: UDP 6: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: TCP 6: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: TCP 6: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IP4disc: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IP4disc: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IP4: 9458 (58.419%)
Dec 18 11:25:59 snort[9630]: IP4: 9458 (58.419%)
Dec 18 11:25:59 snort[9630]: IP6disc: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IP6disc: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IP6opts: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IP6opts: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IP6 EXT: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IP6 EXT: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IPV6: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: IPV6: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: VLAN: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: VLAN: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ETHdisc: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ETHdisc: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: ETH: 16190 (100.000%)
Dec 18 11:25:59 snort[9630]: ETH: 16190 (100.000%)
Dec 18 11:25:59 snort[9630]: Breakdown by protocol (includes rebuilt packets):
Dec 18 11:25:59 snort[9630]: Breakdown by protocol (includes rebuilt packets):
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: Outstanding: 4 (0.025%)
Dec 18 11:25:59 snort[9630]: Outstanding: 4 (0.025%)
Dec 18 11:25:59 snort[9630]: Dropped: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: Dropped: 0 (0.000%)
Dec 18 11:25:59 snort[9630]: Analyzed: 16181 (99.975%)
Dec 18 11:25:59 snort[9630]: Analyzed: 16181 (99.975%)
Dec 18 11:25:59 snort[9630]: Received: 16185
Dec 18 11:25:59 snort[9630]: Received: 16185
Dec 18 11:25:59 snort[9630]: Packet Wire Totals:
Dec 18 11:25:59 snort[9630]: Packet Wire Totals:
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: ===============================================================================
Dec 18 11:25:59 snort[9630]: *** Caught Term-Signal
Dec 18 11:25:59 snort[9630]: *** Caught Term-Signal
Dec 18 11:25:59 kernel: fxp0: promiscuous mode disabled
Dec 18 11:25:58 php: /pkg_mgr_install.php: cd /var/db/pkg && pkg_delete ls | grep snort
Dec 18 11:25:58 php: /pkg_mgr_install.php: cd /var/db/pkg && pkg_delete ls | grep snort-2.8.4.1_5 pkg v.1.7
Dec 18 11:25:52 dhcpd: For info, please visit http://www.isc.org/sw/dhcp/
Dec 18 11:25:52 dhcpd: All rights reserved.
Dec 18 11:25:52 dhcpd: Copyright 2004-2008 Internet Systems Consortium.
Dec 18 11:25:52 dhcpd: Internet Systems Consortium DHCP Server V3.0.7
Dec 18 11:25:51 dnsmasq[12174]: read /etc/hosts - 2 addresses
Dec 18 11:25:51 dnsmasq[12174]: using nameserver 208.67.220.220#53
Dec 18 11:25:51 dnsmasq[12174]: using nameserver 208.67.222.222#53
Dec 18 11:25:51 dnsmasq[12174]: reading /etc/resolv.conf
Dec 18 11:25:51 dnsmasq[12174]: compile time options: IPv6 GNU-getopt BSD-bridge ISC-leasefile no-DBus no-I18N TFTP
Dec 18 11:25:51 dnsmasq[12174]: started, version 2.45 cachesize 150
Dec 18 11:25:50 dnsmasq[5714]: exiting on receipt of SIGTERM
Dec 18 11:23:47 php: /pkg_mgr_install.php: Beginning package installation for DNS Blacklist.Btw I'm not really hung up on fixing this. It only seems to happen once right after I install a fresh copy of pfsense 1.2.3. Afterwards things are functional.
-
It sounds like there is a problem with your config.xml
This likely has nothing to do with snort itself, it's reinstalling all of your packages because it thinks they don't exist or need updated.
Because it keeps happening and isn't fixing itself, there is like an empty xml tag where one is not expected, or some other quirk.
If you could post a sanitized (passwords and other identifying information removed) copy of your config.xml we might be able to figure out what is really going on.
-
I can confirm this I just installed snort on my alix 2d3 and then when clicking on the system main screen it brought me to the packages page and started uninstalling snort..weird
-
I can confirm I had this problem with a clean install of 1.2.3 and after rebooting the machine snort was gone, along with all my config settings when I reinstalled. I don't know what happened, but I haven't restarted since and all is working. I may have to reinstall, but i don't want to out of fear it will happen again.
-
I can confirm I had this problem with a clean install of 1.2.3 and after rebooting the machine snort was gone, along with all my config settings when I reinstalled. I don't know what happened, but I haven't restarted since and all is working. I may have to reinstall, but i don't want to out of fear it will happen again.
Tracked the problem to the old-snort.
Seems old-snort is not uninstalling completely and is conflicting with the new install.
Do a fresh install, sorry I didn't see this coming.
James
-
Seems to be hanging on running deinstall commands.