Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort service will not start

    Scheduled Pinned Locked Moved pfSense Packages
    13 Posts 3 Posters 11.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V Offline
      Visseroth
      last edited by

      1.2.3-Release
      2.8.4.1_5 pkg v.1.7

      1 Reply Last reply Reply Quote 0
      • J Offline
        jamesdean
        last edited by

        @Visseroth:

        1.2.3-Release
        2.8.4.1_5 pkg v.1.7

        I need the output of

        ls /usr/local/etc/rc.d

        and

        cat /usr/local/etc/rc.d/mysnort_interface.sh

        James

        1 Reply Last reply Reply Quote 0
        • V Offline
          Visseroth
          last edited by

          bandwidthd.sh          mbmon                  snort.sh
          bandwidthd.sh.sample    proxy_monitor.sh        squid.sh
          imspector              snmpd
          imspector.sh            snmptrapd

          cat: /usr/local/etc/rc.d/mysnort_interface.sh: No such file or directory

          1 Reply Last reply Reply Quote 0
          • J Offline
            jamesdean
            last edited by

            @Visseroth:

            bandwidthd.sh           mbmon                   snort.sh
            bandwidthd.sh.sample    proxy_monitor.sh        squid.sh
            imspector               snmpd
            imspector.sh            snmptrapd

            cat: /usr/local/etc/rc.d/mysnort_interface.sh: No such file or directory

            Type this in the command terminal and post the error.

            /usr/local/bin/snort -c /usr/local/etc/snort/snort.conf -l /var/log/snort -D -i ngo

            James

            1 Reply Last reply Reply Quote 0
            • V Offline
              Visseroth
              last edited by

              command came back with no error, no report….....

              /usr/local/bin/snort -c /usr/local/etc/snort/snort.conf -l /var/log/snort -D -i ngo

              Edit: Checked the system logs and found this error.........

              snort[42700]: FATAL ERROR: Unable to open rules file: /usr/local/etc/snort/rules/attack-responses.rules or /usr/local/etc/snort//usr/local/etc/snort/rules/attack-responses.rules

              1 Reply Last reply Reply Quote 0
              • J Offline
                jamesdean
                last edited by

                I see what going on.

                Update all your rules, befor starting snort..

                James

                1 Reply Last reply Reply Quote 0
                • V Offline
                  Visseroth
                  last edited by

                  I keep getting

                  Please wait… You may only check for New Rules every 15 minutes...

                  1 Reply Last reply Reply Quote 0
                  • V Offline
                    Visseroth
                    last edited by

                    OK, if the rules won't update automaticly is there another way to update them?

                    1 Reply Last reply Reply Quote 0
                    • V Offline
                      Visseroth
                      last edited by

                      Any update please?

                      1 Reply Last reply Reply Quote 0
                      • T Offline
                        tester_02
                        last edited by

                        I've also had this issue randomly on installs/upgrades.  Do you have premium rules?  If so, turn it off, wait and then do the update.  I have no theory as to why it happens, but after that, I can set the premium rules on and it works from there on until the next snort update.

                        a.r.

                        1 Reply Last reply Reply Quote 0
                        • V Offline
                          Visseroth
                          last edited by

                          I have Snort subscriber enabled and have the key inserted but disabling it doesn't allow it to start and still nothing shows up in the system logs.
                          I have disabled all options and saved, still no starting of the service. I have reinstalled everything and still no starting of the service.

                          I'm quite literally stumped, I've even tried reinstalling.

                          The only message I get when trying to update is …....
                          Please wait... You may only check for New Rules every 15 minutes...

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.