Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort service will not start

    Scheduled Pinned Locked Moved pfSense Packages
    13 Posts 3 Posters 11.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jamesdean
      last edited by

      @Visseroth:

      1.2.3-Release
      2.8.4.1_5 pkg v.1.7

      I need the output of

      ls /usr/local/etc/rc.d

      and

      cat /usr/local/etc/rc.d/mysnort_interface.sh

      James

      1 Reply Last reply Reply Quote 0
      • V Offline
        Visseroth
        last edited by

        bandwidthd.sh          mbmon                  snort.sh
        bandwidthd.sh.sample    proxy_monitor.sh        squid.sh
        imspector              snmpd
        imspector.sh            snmptrapd

        cat: /usr/local/etc/rc.d/mysnort_interface.sh: No such file or directory

        1 Reply Last reply Reply Quote 0
        • J Offline
          jamesdean
          last edited by

          @Visseroth:

          bandwidthd.sh           mbmon                   snort.sh
          bandwidthd.sh.sample    proxy_monitor.sh        squid.sh
          imspector               snmpd
          imspector.sh            snmptrapd

          cat: /usr/local/etc/rc.d/mysnort_interface.sh: No such file or directory

          Type this in the command terminal and post the error.

          /usr/local/bin/snort -c /usr/local/etc/snort/snort.conf -l /var/log/snort -D -i ngo

          James

          1 Reply Last reply Reply Quote 0
          • V Offline
            Visseroth
            last edited by

            command came back with no error, no report….....

            /usr/local/bin/snort -c /usr/local/etc/snort/snort.conf -l /var/log/snort -D -i ngo

            Edit: Checked the system logs and found this error.........

            snort[42700]: FATAL ERROR: Unable to open rules file: /usr/local/etc/snort/rules/attack-responses.rules or /usr/local/etc/snort//usr/local/etc/snort/rules/attack-responses.rules

            1 Reply Last reply Reply Quote 0
            • J Offline
              jamesdean
              last edited by

              I see what going on.

              Update all your rules, befor starting snort..

              James

              1 Reply Last reply Reply Quote 0
              • V Offline
                Visseroth
                last edited by

                I keep getting

                Please wait… You may only check for New Rules every 15 minutes...

                1 Reply Last reply Reply Quote 0
                • V Offline
                  Visseroth
                  last edited by

                  OK, if the rules won't update automaticly is there another way to update them?

                  1 Reply Last reply Reply Quote 0
                  • V Offline
                    Visseroth
                    last edited by

                    Any update please?

                    1 Reply Last reply Reply Quote 0
                    • T Offline
                      tester_02
                      last edited by

                      I've also had this issue randomly on installs/upgrades.  Do you have premium rules?  If so, turn it off, wait and then do the update.  I have no theory as to why it happens, but after that, I can set the premium rules on and it works from there on until the next snort update.

                      a.r.

                      1 Reply Last reply Reply Quote 0
                      • V Offline
                        Visseroth
                        last edited by

                        I have Snort subscriber enabled and have the key inserted but disabling it doesn't allow it to start and still nothing shows up in the system logs.
                        I have disabled all options and saved, still no starting of the service. I have reinstalled everything and still no starting of the service.

                        I'm quite literally stumped, I've even tried reinstalling.

                        The only message I get when trying to update is …....
                        Please wait... You may only check for New Rules every 15 minutes...

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.