Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort, problem with startup services

    Scheduled Pinned Locked Moved pfSense Packages
    16 Posts 3 Posters 6.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jamesdean
      last edited by

      simby

      Sorry, this all my fault.

      There is a bug in snort-dev, rule files are not being copied over after updates.
      Rules are only being copied after interface creation.

      Fix

      Manually copy "cp /usr/local/etc/snort/rules* /usr/local/etc/snort/snort_myinterface/rules

      or

      Delete all your interfaces.
      Update your rules.
      Create your interfaces.

      Merry Christmas
      James

      1 Reply Last reply Reply Quote 0
      • S Offline
        simby
        last edited by

        Thanks, fixed now. Do i need to do this on every update of snort rules?

        1 Reply Last reply Reply Quote 0
        • S Offline
          simby
          last edited by

          now i have this problem:

          Loading dynamic engine /usr/local/lib/snort_dynamicengine/libsf_engine.so… ERROR: Failed to load /usr/local/lib/snort_dynamicengine/libsf_engine.so: Cannot open "/usr/local/lib/snort_dynamicengine/libsf_engine.so"
          Fatal Error, Quitting..

          1 Reply Last reply Reply Quote 0
          • J Offline
            jamesdean
            last edited by

            @simby:

            now i have this problem:

            Loading dynamic engine /usr/local/lib/snort_dynamicengine/libsf_engine.so… ERROR: Failed to load /usr/local/lib/snort_dynamicengine/libsf_engine.so: Cannot open "/usr/local/lib/snort_dynamicengine/libsf_engine.so"
            Fatal Error, Quitting..

            Reinstall the snort-dev package I added code today.

            Fallow my changes at https://rcs.pfsense.org/users/robiscool

            James

            1 Reply Last reply Reply Quote 0
            • S Offline
              simby
              last edited by

              Thanks!!! & for link :)

              1 Reply Last reply Reply Quote 0
              • T Offline
                ToxIcon
                last edited by

                pfsense 1.2.3-RELEASE
                snort-dev  2.8.4.1_7 pkg v. 1.8

                short Rules tab error:
                please work Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 35 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 36 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 37 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 38 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 39

                cant save/apply enable new rules

                snort to dashboard  gives 404 - Not Found

                1 Reply Last reply Reply Quote 0
                • J Offline
                  jamesdean
                  last edited by

                  @ToxIcon:

                  pfsense 1.2.3-RELEASE
                  snort-dev  2.8.4.1_7 pkg v. 1.8

                  short Rules tab error:
                  please work Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 35 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 36 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 37 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 38 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 39

                  cant save/apply enable new rules

                  snort to dashboard  gives 404 - Not Found

                  Updated code…...
                  Am all done with snort_blocked.php and snort_alerts.php.

                  snort_rules.php is to slow.

                  Im adding code to make it faster.

                  James

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    simby
                    last edited by

                    On alerts blocked we have this error:

                    Warning: array_unique(): The argument should be an array in /usr/local/www/snort/snort_blocked.php on line 345 Warning: Invalid argument supplied for foreach() in /usr/local/www/snort/snort_blocked.php on line 350 ;)

                    1 Reply Last reply Reply Quote 0
                    • J Offline
                      jamesdean
                      last edited by

                      I have just tested and the code works.

                      Do you have the latest code ?

                      Do you have alerts that are not blocked ?

                      James

                      1 Reply Last reply Reply Quote 0
                      • S Offline
                        simby
                        last edited by

                        Yes, i have the last code from today,… i will add you later picture.

                        1 Reply Last reply Reply Quote 0
                        • S Offline
                          simby
                          last edited by

                          Picture,… can you please fix this log reporting to fix the new theme :)

                          snapshot1.png
                          snapshot1.png_thumb
                          snapshot2.png
                          snapshot2.png_thumb

                          1 Reply Last reply Reply Quote 0
                          • J Offline
                            jamesdean
                            last edited by

                            @simby:

                            Picture,… can you please fix this log reporting to fix the new theme :)

                            Updated code to deal with corrupted alerts file, said error should be fixed now.

                            Now Im working on snort_rules.php trying to make it faster.

                            James

                            1 Reply Last reply Reply Quote 0
                            • T Offline
                              ToxIcon
                              last edited by

                              snort-dev 2.8.4.1_7 pkg v. 1.8

                              PROTO:255  (portscan) UDP Filtered Portsweep  Prep  x.x.x.x  empty  ->  x.x.x.x  empty  122:23:0  01/03-16:46:06

                              what snort rule triggers the alert above

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.