Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort, problem with startup services

    Scheduled Pinned Locked Moved pfSense Packages
    16 Posts 3 Posters 6.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      simby
      last edited by

      Thanks, fixed now. Do i need to do this on every update of snort rules?

      1 Reply Last reply Reply Quote 0
      • S
        simby
        last edited by

        now i have this problem:

        Loading dynamic engine /usr/local/lib/snort_dynamicengine/libsf_engine.so… ERROR: Failed to load /usr/local/lib/snort_dynamicengine/libsf_engine.so: Cannot open "/usr/local/lib/snort_dynamicengine/libsf_engine.so"
        Fatal Error, Quitting..

        1 Reply Last reply Reply Quote 0
        • J
          jamesdean
          last edited by

          @simby:

          now i have this problem:

          Loading dynamic engine /usr/local/lib/snort_dynamicengine/libsf_engine.so… ERROR: Failed to load /usr/local/lib/snort_dynamicengine/libsf_engine.so: Cannot open "/usr/local/lib/snort_dynamicengine/libsf_engine.so"
          Fatal Error, Quitting..

          Reinstall the snort-dev package I added code today.

          Fallow my changes at https://rcs.pfsense.org/users/robiscool

          James

          1 Reply Last reply Reply Quote 0
          • S
            simby
            last edited by

            Thanks!!! & for link :)

            1 Reply Last reply Reply Quote 0
            • T
              ToxIcon
              last edited by

              pfsense 1.2.3-RELEASE
              snort-dev  2.8.4.1_7 pkg v. 1.8

              short Rules tab error:
              please work Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 35 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 36 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 37 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 38 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 39

              cant save/apply enable new rules

              snort to dashboard  gives 404 - Not Found

              1 Reply Last reply Reply Quote 0
              • J
                jamesdean
                last edited by

                @ToxIcon:

                pfsense 1.2.3-RELEASE
                snort-dev  2.8.4.1_7 pkg v. 1.8

                short Rules tab error:
                please work Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 35 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 36 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 37 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 38 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 39

                cant save/apply enable new rules

                snort to dashboard  gives 404 - Not Found

                Updated code…...
                Am all done with snort_blocked.php and snort_alerts.php.

                snort_rules.php is to slow.

                Im adding code to make it faster.

                James

                1 Reply Last reply Reply Quote 0
                • S
                  simby
                  last edited by

                  On alerts blocked we have this error:

                  Warning: array_unique(): The argument should be an array in /usr/local/www/snort/snort_blocked.php on line 345 Warning: Invalid argument supplied for foreach() in /usr/local/www/snort/snort_blocked.php on line 350 ;)

                  1 Reply Last reply Reply Quote 0
                  • J
                    jamesdean
                    last edited by

                    I have just tested and the code works.

                    Do you have the latest code ?

                    Do you have alerts that are not blocked ?

                    James

                    1 Reply Last reply Reply Quote 0
                    • S
                      simby
                      last edited by

                      Yes, i have the last code from today,… i will add you later picture.

                      1 Reply Last reply Reply Quote 0
                      • S
                        simby
                        last edited by

                        Picture,… can you please fix this log reporting to fix the new theme :)

                        snapshot1.png
                        snapshot1.png_thumb
                        snapshot2.png
                        snapshot2.png_thumb

                        1 Reply Last reply Reply Quote 0
                        • J
                          jamesdean
                          last edited by

                          @simby:

                          Picture,… can you please fix this log reporting to fix the new theme :)

                          Updated code to deal with corrupted alerts file, said error should be fixed now.

                          Now Im working on snort_rules.php trying to make it faster.

                          James

                          1 Reply Last reply Reply Quote 0
                          • T
                            ToxIcon
                            last edited by

                            snort-dev 2.8.4.1_7 pkg v. 1.8

                            PROTO:255  (portscan) UDP Filtered Portsweep  Prep  x.x.x.x  empty  ->  x.x.x.x  empty  122:23:0  01/03-16:46:06

                            what snort rule triggers the alert above

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.