Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort, problem with startup services

    Scheduled Pinned Locked Moved pfSense Packages
    16 Posts 3 Posters 6.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jamesdean
      last edited by

      @simby:

      now i have this problem:

      Loading dynamic engine /usr/local/lib/snort_dynamicengine/libsf_engine.so… ERROR: Failed to load /usr/local/lib/snort_dynamicengine/libsf_engine.so: Cannot open "/usr/local/lib/snort_dynamicengine/libsf_engine.so"
      Fatal Error, Quitting..

      Reinstall the snort-dev package I added code today.

      Fallow my changes at https://rcs.pfsense.org/users/robiscool

      James

      1 Reply Last reply Reply Quote 0
      • S Offline
        simby
        last edited by

        Thanks!!! & for link :)

        1 Reply Last reply Reply Quote 0
        • T Offline
          ToxIcon
          last edited by

          pfsense 1.2.3-RELEASE
          snort-dev  2.8.4.1_7 pkg v. 1.8

          short Rules tab error:
          please work Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 35 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 36 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 37 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 38 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 39

          cant save/apply enable new rules

          snort to dashboard  gives 404 - Not Found

          1 Reply Last reply Reply Quote 0
          • J Offline
            jamesdean
            last edited by

            @ToxIcon:

            pfsense 1.2.3-RELEASE
            snort-dev  2.8.4.1_7 pkg v. 1.8

            short Rules tab error:
            please work Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 35 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 36 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 37 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 38 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/www/snort/snort_rules.php:390) in /usr/local/www/guiconfig.inc on line 39

            cant save/apply enable new rules

            snort to dashboard  gives 404 - Not Found

            Updated code…...
            Am all done with snort_blocked.php and snort_alerts.php.

            snort_rules.php is to slow.

            Im adding code to make it faster.

            James

            1 Reply Last reply Reply Quote 0
            • S Offline
              simby
              last edited by

              On alerts blocked we have this error:

              Warning: array_unique(): The argument should be an array in /usr/local/www/snort/snort_blocked.php on line 345 Warning: Invalid argument supplied for foreach() in /usr/local/www/snort/snort_blocked.php on line 350 ;)

              1 Reply Last reply Reply Quote 0
              • J Offline
                jamesdean
                last edited by

                I have just tested and the code works.

                Do you have the latest code ?

                Do you have alerts that are not blocked ?

                James

                1 Reply Last reply Reply Quote 0
                • S Offline
                  simby
                  last edited by

                  Yes, i have the last code from today,… i will add you later picture.

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    simby
                    last edited by

                    Picture,… can you please fix this log reporting to fix the new theme :)

                    snapshot1.png
                    snapshot1.png_thumb
                    snapshot2.png
                    snapshot2.png_thumb

                    1 Reply Last reply Reply Quote 0
                    • J Offline
                      jamesdean
                      last edited by

                      @simby:

                      Picture,… can you please fix this log reporting to fix the new theme :)

                      Updated code to deal with corrupted alerts file, said error should be fixed now.

                      Now Im working on snort_rules.php trying to make it faster.

                      James

                      1 Reply Last reply Reply Quote 0
                      • T Offline
                        ToxIcon
                        last edited by

                        snort-dev 2.8.4.1_7 pkg v. 1.8

                        PROTO:255  (portscan) UDP Filtered Portsweep  Prep  x.x.x.x  empty  ->  x.x.x.x  empty  122:23:0  01/03-16:46:06

                        what snort rule triggers the alert above

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.