Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort Problems

    Scheduled Pinned Locked Moved pfSense Packages
    16 Posts 11 Posters 10.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      warzac
      last edited by

      I have the same probléme. the manuelly upgrade not work and snort don't work normally.
      Anybody can help me

      1 Reply Last reply Reply Quote 0
      • B
        blueknigh7
        last edited by

        @JustinHoMi:

        Tried updating the rules manually, and getting this error:

        snort[63763]: FATAL ERROR: Dynamic detection lib /usr/local/lib/snort/dynamicrules//lib_sfdynamic_example_rule.so 1.0 isn't compatible with the current dynamic engine library /usr/local/lib/snort/dynamicengine/libsf_engine.so 1.10. The dynamic detection lib is compiled with an older version of the dynamic engine.

        Any thoughts? I tried uninstalling/reinstalling, same thing. Might not be related.

        Edit: resolved by deleting /usr/local/lib/snort/dynamicrules/lib_sfdynamic_example_rule.so

        I have the exact same error.  I did the same thing and renamed/deleted the file.

        1 Reply Last reply Reply Quote 0
        • ?
          A Former User
          last edited by

          :( I tryed the manual update and does not seem to work for me .What happened with snort it worked so well for so long and the last time i stopped using Pfsense was because of this same problem .I have no idea why people have to play with things when they work perfectly .
          Has anyone found out the problem yet .Snort still will not update and there is no errors ..

          1 Reply Last reply Reply Quote 0
          • D
            davidindesignlondon.co.u
            last edited by

            Thanks JustinHoMi,

            Worked perfectly! :)

            –----------------------
            Live with passion

            1 Reply Last reply Reply Quote 0
            • N
              nufer
              last edited by

              I had the same problem.

              solved by changing to basic rules in Global Configuration tab

              1 Reply Last reply Reply Quote 0
              • 0
                0tt0
                last edited by

                @nufer:

                I had the same problem.

                solved by changing to basic rules in Global Configuration tab

                Doesn't premium rules require a subscription? (And NOT just an Oinkcode=registration)

                1 Reply Last reply Reply Quote 0
                • L
                  LostInIgnorance
                  last edited by

                  With the premium rules, I am noticing I am not able to update them and I keep getting errors of:

                  Directory so_rules does not exist…

                  Error copying so_rules...

                  I use the basic and it updates fine.  I know snort came up with a new program two days ago.

                  1 Reply Last reply Reply Quote 0
                  • G
                    g4m3c4ck
                    last edited by

                    Lost: Broke for me too but I manually fixed it in this thread.http://forum.pfsense.org/index.php/topic,24434.15.html

                    1 Reply Last reply Reply Quote 0
                    • P
                      pneumoboy
                      last edited by

                      Hello all…

                      I am running 1.2.3 with snort 2.8.5.3 v1.22 (upgraded two days ago after the so directory error appeared).

                      I cannot update my rules when I have the "Premium Rules" box check (despite being a snort VRT subscriber). I had to select "Basic Rules" in order to get the updates.

                      Right now I am not sure I am getting the most recent/up-to-date rules from snort, or if I am getting the 30-day (non-subscriber) rules. I know there are different URLs for the rule snapshots depending on if you are just registered or if you are a subscriber.

                      I see others are having this problem, but I have not seen a definite fix. Any suggestion?

                      1 Reply Last reply Reply Quote 0
                      • P
                        pneumoboy
                        last edited by

                        Good news! Just saw an updated snort package is out. Version 2.8.5.3 pkg v. 1.23 is working with Premium Rules. Not only was I able to download all the rules, but snort started with no errors when I enabled every category (with defaults) on the WAN interface.

                        Thanks to the pfSense team for an awesome product!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.