Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort…working on Bugs today.....

    Scheduled Pinned Locked Moved pfSense Packages
    26 Posts 11 Posters 12.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      grandrivers
      last edited by

      how hard is it to add the autoshun rules I tried to do it my manually adding them but caused snort not to start because it said snort didn't recognize  the autoshun rules not sure if the snort binary has to be patched to get them to work?

      pfsense plus 25.03 super micro A1SRM-2558F
      C2558 32gig ECC  60gig SSD

      1 Reply Last reply Reply Quote 0
      • J Offline
        jamesdean
        last edited by

        @grandrivers:

        how hard is it to add the autoshun rules I tried to do it my manually adding them but caused snort not to start because it said snort didn't recognize  the autoshun rules not sure if the snort binary has to be patched to get them to work?

        You need a patch binary with autoshun code to use there rules.

        I will add that at some point mainly because I want that p0f code.

        James

        1 Reply Last reply Reply Quote 0
        • G Offline
          grandrivers
          last edited by

          ok I think i'll wait being mainly versed in windows not sure I am ready to try this level change to pfsense
          thanks for the info and hard work

          pfsense plus 25.03 super micro A1SRM-2558F
          C2558 32gig ECC  60gig SSD

          1 Reply Last reply Reply Quote 0
          • ? This user is from outside of this forum
            Guest
            last edited by

            We ran into a couple commercial support customers who have run into an issue of the snort log filling up their hard drive (the same has been reported on the forums).  There is no log rotation happening with the snort logs, is this something you're aware of and/or planning to fix?

            1 Reply Last reply Reply Quote 0
            • H Offline
              Hugovsky
              last edited by

              Well, time to report about snort…

              1.2.3-RELEASE
              built on Sun Dec 6 23:38:21 EST 2009
              FreeBSD 7.2-RELEASE-p5 i386
              Snort 2.8.5.3 pkg v. 1.21

              specs:

              Intel(R) Pentium(R) 4 CPU 2.00GHz
              1 GB ram

              2 lan and 1 wan on ADSL 16bits/1mbits and 1 wan on Fibre 100mbits. Snort running on all interfaces.

              300+ clients daily.

              Snort installed well. No problems at all. Updates well also. Using whitelists with no problems.
              Only issue I've discovered is lack of log rotation. Plus, when clicking clear button, seems to stop snort. It only logs again after stoping and starting snort again on all interfaces. Other than that, you're the man, James! ;)

              And a special thank's to ALL THAT PARTICIPATE AND MAKE PFSENSE GROW AND IMPROVE....

              1 Reply Last reply Reply Quote 0
              • J Offline
                jwbrown77
                last edited by

                Running: pfSense 1.2.3
                Upgraded Snort Today To: 2.8.5.3 pkg v. 1.22

                I was getting the following error when attempting to start any individual Snort service:

                snort[1183]: FATAL ERROR: /usr/local/etc/snort/snort.conf(180) => Invalid ip_list to 'ignore_scanners' option

                There was no comma being inserted after the localhost IP in HOME_NET, so it was running into the next address (127.0.0.155.55.55.55 instead of 127.0.0.1,55.55.55.55)

                I edited /usr/local/pkg/snort/snort.inc, line 122, to add a comma at the end of 127.0.0.1 and that fixed it (though I suspect it's not really the proper fix):

                $home_net .= "127.0.0.1,";

                1 Reply Last reply Reply Quote 0
                • J Offline
                  jwbrown77
                  last edited by

                  Thanks James.

                  All the other HOME_NET IPs (in my config at least) were comma separated, so I figured that one should be as well.

                  No issues starting Snort after that, though I admit I haven't tested it yet to see if it actually triggers alerts.

                  1 Reply Last reply Reply Quote 0
                  • H Offline
                    Hugovsky
                    last edited by

                    One more thing. I've updated and noticed that snort didn't kept my configurations. Is this supposed to be this way?

                    1 Reply Last reply Reply Quote 0
                    • J Offline
                      jwbrown77
                      last edited by

                      Low priority suggestion:

                      It would be nice to be able to have an "add similar ruleset to this one" button.  Checking off all the rulesets to load when you're running on multiple interfaces can be time consuming.

                      1 Reply Last reply Reply Quote 0
                      • C Offline
                        chowtamah
                        last edited by

                        Thank you James, for upgrading snort on pfsense.

                        A special thank's to all who improve pfsense.

                        2.0.2-RELEASE (amd64)  &  2.2.2-RELEASE (amd64)

                        Always trying to learn!!

                        1 Reply Last reply Reply Quote 0
                        • V Offline
                          vronp
                          last edited by

                          Well, it sure seems like the whitelist is not working.

                          Anybody else have trouble with the whitelist?

                          1 Reply Last reply Reply Quote 0
                          • D Offline
                            DigitalJer
                            last edited by

                            @vronp:

                            Well, it sure seems like the whitelist is not working.

                            …working great for me.  I've whitelisted a cpl websites (that were initially blocked by SNORT), and my work IP address (so I can VPN into my home stuff while at work); no problems whatsoever.

                            –------------------------------------------------
                            2.4.3-RELEASE (amd64)
                            built on Mon Mar 26 18:02:04 CDT 2018
                            FreeBSD 11.1-RELEASE-p7
                            VM in ESXi 5.5
                            1 x 1000baseTX (WAN)
                            1 x 1000baseTX (LAN)

                            1 Reply Last reply Reply Quote 0
                            • G Offline
                              grandrivers
                              last edited by

                              i am trying to create a new whitelist add the button doesn't function to add another entry tried on ff3.6 and chrome and ie 8

                              pfsense plus 25.03 super micro A1SRM-2558F
                              C2558 32gig ECC  60gig SSD

                              1 Reply Last reply Reply Quote 0
                              • J Offline
                                jamesdean
                                last edited by

                                I just tested and verified that the add button on IE8, firefox 3.6.3 and chrome works. Im using the same code as firewall_aliases_edit.php does that work for you?

                                Do you have scripting enabled ?

                                Tell me more about the system your browsers are on.

                                James

                                1 Reply Last reply Reply Quote 0
                                • G Offline
                                  grandrivers
                                  last edited by

                                  i am running windows7 pro retested on chrome and ff3.6.3 and  firewall_aliases_edit.php does work just fine

                                  ie has this error blip Webpage error details

                                  User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
                                  Timestamp: Sun, 25 Apr 2010 23:13:43 UTC

                                  Message: 'rowname' is undefined
                                  Line: 147
                                  Char: 2
                                  Code: 0
                                  URI: https://192.168.35.1/snort/snort_interfaces_whitelist_edit.php?id=0

                                  pfsense plus 25.03 super micro A1SRM-2558F
                                  C2558 32gig ECC  60gig SSD

                                  1 Reply Last reply Reply Quote 0
                                  • T Offline
                                    tester_02
                                    last edited by

                                    I have a friend who is getting blocked by snort periodically. All he is accessing is my email server.  With this going on, I also noticed that the logging is really not all that helpfull..  Here is what the log shows..

                                    8  3  PROTO:255  (portscan) UDP Distributed Portscan  Prep  xxx.xxx.xxx.xxx  empty  ->  xxx.xxx.xxx.xxx  empty  122:20:0  04/25-20:44:30

                                    Basically what rule is causing this false positive?  I am guessing the port scan pre-processor?  If so, I guess I just have to turn it off to not block legit users?

                                    Anyone notice their memory usage go up since the .22 release?  My memory usage went up, and seems to be creeping up every day now.  With the old version (.20 last for me) it was lower and stable.

                                    1 Reply Last reply Reply Quote 0
                                    • H Offline
                                      Hugovsky
                                      last edited by

                                      I confirm a problem with the box in whitelists. It works in IE 8 and 7. With Firefox it doesn't show the box to enter the ip. It works well in the aliases.

                                      pfsense.JPG
                                      pfsense.JPG_thumb
                                      pfsense1.JPG
                                      pfsense1.JPG_thumb

                                      1 Reply Last reply Reply Quote 0
                                      • G Offline
                                        grandrivers
                                        last edited by

                                        james my system is pfsense 2.0 I am seeing the box to enter 1 ip but cant get it to add more boxes the firewall_aliases_edit.php does work

                                        pfsense plus 25.03 super micro A1SRM-2558F
                                        C2558 32gig ECC  60gig SSD

                                        1 Reply Last reply Reply Quote 0
                                        • V Offline
                                          vronp
                                          last edited by

                                          @DigitalJer:

                                          @vronp:

                                          Well, it sure seems like the whitelist is not working.

                                          …working great for me.  I've whitelisted a cpl websites (that were initially blocked by SNORT), and my work IP address (so I can VPN into my home stuff while at work); no problems whatsoever.

                                          A VOIP authentication server keeps popping up on my alert and block list despite having it listed in the whitelist.

                                          I wonder if it is due to some of the snort rules I have selected ??

                                          1 Reply Last reply Reply Quote 0
                                          • G Offline
                                            g4m3c4ck
                                            last edited by

                                            I am going to look into it more but the latest rules have broke all versions of snort for pfsense due to a missing directory for so_rules. I was just wondering if anyone else was experinceing this or was it just me.

                                            pfsence 1.2.3 release both versions of snort.

                                            Edit: Just notice a 0 byte file called touch off of root. Not sure if this is due to snort script but I have not noticed it before.

                                            Edit:Edit: I also noticed when I edit my VLAN interfaces in 2.8.5.3 pkg v. 1.22 it says "Snort: Interface Edit: 0 57641 vlan0" instead of what I have them aliased as.

                                            Edit:Edit:Edit: Hmm I checked /usr/local/pkg/snort/snort_check_for_rules_updates.php and it seems that anything that would generate that error is already commented out. wth I am kinda scared to try and reboot pfsense and see if that will fix it.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.