Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort Updating problems !!!

    Scheduled Pinned Locked Moved pfSense Packages
    72 Posts 27 Posters 37.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rnowotny
      last edited by

      Dear g4m3c4ck,
      I dont wanted to be rude at all, just giving some input what might make sense.
      So if my post seems to be unpolite, I apologize.
      You may have noticed that I posted a tiny shellscript some posts before,
      to make a manual update of snortrules via cronjob. Not a big deal - but some rookies might use it.
      I might come up with a script that preserve the ON/OFF state for each IDS across updates,
      because I need it myself ;-)

      Yours sincerely
      Robert

      @g4m3c4ck:

      Dear rnowotny,
         Being the newbie you are. If you already knew the time James and many others have already spent on the pfsense project as well as the complexity of doing so you would not have worded or made the statements in the way you did. pfSense is a great and very powerful project that you use for FREE. If you want to contribute to the project please do so but in the proper way. Basically, I am asking you to put up or shut up.

      Sincerly,

      Avid pfSense/Snort user and appeciator

      1 Reply Last reply Reply Quote 0
      • E
        EZ
        last edited by

        Alright. I dug through my code folder and found this price. Its using fstockopen opt. to pull a redirected url. Its not what I was looking for but might do the job. Ill test it tonight and see if I can pull down the monster url from snort. If I have any luck Ill post my finished pages for inspection.
        Take it EZ.

        url_redirect.txt

        1 Reply Last reply Reply Quote 0
        • D
          darklogic
          last edited by

          rnowotny

          I understand what you are saying on a lot of your post. I agree with most statements on the rules and there are better ways to make sure rules are enabled and disabled after updates. These are all the same issues that others are dealing with. James Dean picked up on the SNORT project when no one else did, he also has contributed endless hours to the programming and online fourms. SNORT is getting better and better. I realize you may mean no harm, but your wording is kind of blunt!!! Different people online are going to take your words differently from others. Statements like posting scripts online so some rookies may use it is not what I would call appropriate commits. The fact that anyone on these forums and using pfsense says to me that hey, no one here is really a rookie.

          Take Care,

          Matt

          1 Reply Last reply Reply Quote 0
          • D
            djnicofun
            last edited by

            hello,

            I use Pfsense V1.2.3-RC1 , a have install package : Snort : 2.8.6 pkg v. 1.27

            i have find a bug , to update the rules the filename of the rules has change since : 10 junes 2010

            the file name is now :
            snortrules-snapshot-2860.tar.gz

            Example for snort 2.8.6.0:
                  url = http://www.snort.org/pub-bin/oinkmaster.cgi/XXXXXXXXXXXXXX/snortrules-snapshot-2860.tar.gz

            Important Note from SNORT website:
            We are changing the way we publish rules. In June 2010 we stopped offering rules in the "snortrules-snapshot-CURRENT" format. Instead, rules are released for specific versions of Snort. You will be responsible for downloading the correct rules release for your version of Snort. The new versioning mechanism will require a four digit version in the file name.

            Please James can you update the package ?

            Best reagrds

            1 Reply Last reply Reply Quote 0
            • D
              djnicofun
              last edited by

              Where is the file : oinkmaster.conf  on pfsense vers: 1.2.21 ??

              1 Reply Last reply Reply Quote 0
              • R
                rnowotny
                last edited by

                Please check this post, it is a quick and dirty workaround until the new version is avail :

                http://forum.pfsense.org/index.php/topic,26382.msg139375.html#msg139375

                @djnicofun:

                hello,

                I use Pfsense V1.2.3-RC1 , a have install package : Snort : 2.8.6 pkg v. 1.27

                i have find a bug , to update the rules the filename of the rules has change since : 10 junes 2010

                the file name is now :
                snortrules-snapshot-2860.tar.gz

                Example for snort 2.8.6.0:
                      url = http://www.snort.org/pub-bin/oinkmaster.cgi/XXXXXXXXXXXXXX/snortrules-snapshot-2860.tar.gz

                Important Note from SNORT website:
                We are changing the way we publish rules. In June 2010 we stopped offering rules in the "snortrules-snapshot-CURRENT" format. Instead, rules are released for specific versions of Snort. You will be responsible for downloading the correct rules release for your version of Snort. The new versioning mechanism will require a four digit version in the file name.

                Please James can you update the package ?

                Best reagrds

                1 Reply Last reply Reply Quote 0
                • D
                  djnicofun
                  last edited by

                  hi,

                  Ok thanck you, but i have already read this post, i would like know if an official update of this package will be done or not ?

                  best regards.

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    Well they're tricky guys there at Sourcefire. There were a couple things wrong with the rule downloads:

                    1. The URL changed.
                    2. They now redirect you to an Amazon s3 URL to get the actual rules
                    3. The Amazon url is HTTPS.

                    So I fixed the URL, changed a redirect option, and I had to disable cURL's SSL validation, but now the rules download for me.

                    The new package version is up now, give it a try and see if it works.

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • C
                      c0urier
                      last edited by

                      Giving it a try now. Will post back soon!

                      Update:
                      Seems to be working just fine - Rules updated and Snort running. Thanks jimp!!!

                      pfsense: 2.1.5-RELEASE, AMD64
                      Running on: MB/CPU: ASUS P8H77-I / Core i3-2120T | MEM: 8GB DDR3 | HDD: WD Blue 120GB 2.5" SATA | WAN/LAN: Fujitsu D2735-2 – Intel® chip 82576NS | WLAN: Realtek® 8111F PCIe | Connection: 1000/1000Mbit (Bredband2.com)
                      [/U

                      1 Reply Last reply Reply Quote 0
                      • N
                        netmethods
                        last edited by

                        I tried it on all 3 of my pfSense boxes and is working fine. Thanks again Jim!

                        -Jason

                        2x Nexcom 1088n8 in HA config
                        2.4 GHz Quad Core / 4GB DDR2 / SATAII 160GB / 4x1GB Intel module

                        1 Reply Last reply Reply Quote 0
                        • D
                          DigitalJer
                          last edited by

                          Looking good here!

                          Many thanks…

                          –------------------------------------------------
                          2.4.3-RELEASE (amd64)
                          built on Mon Mar 26 18:02:04 CDT 2018
                          FreeBSD 11.1-RELEASE-p7
                          VM in ESXi 5.5
                          1 x 1000baseTX (WAN)
                          1 x 1000baseTX (LAN)

                          1 Reply Last reply Reply Quote 0
                          • ?
                            A Former User
                            last edited by

                            I uninstalled the old package and installed the new one and updated it no problem did a port scan test and all is working (fingers crossed) . ;D

                            1 Reply Last reply Reply Quote 0
                            • T
                              tester_02
                              last edited by

                              Question for those brave people that updated (no going back) :)
                              Premium rules or basic rules?

                              Hoping people have tested both…

                              1 Reply Last reply Reply Quote 0
                              • L
                                LostInIgnorance
                                last edited by

                                I used the subscribed rules and everything is working great over here

                                1 Reply Last reply Reply Quote 0
                                • D
                                  DigitalJer
                                  last edited by

                                  Basic working fine for me.

                                  –------------------------------------------------
                                  2.4.3-RELEASE (amd64)
                                  built on Mon Mar 26 18:02:04 CDT 2018
                                  FreeBSD 11.1-RELEASE-p7
                                  VM in ESXi 5.5
                                  1 x 1000baseTX (WAN)
                                  1 x 1000baseTX (LAN)

                                  1 Reply Last reply Reply Quote 0
                                  • T
                                    tester_02
                                    last edited by

                                    Thanks for the feedback!  I'll give it a whirl…

                                    1 Reply Last reply Reply Quote 0
                                    • C
                                      chowtamah
                                      last edited by

                                      Thanks Jimp.

                                      Snort now updates and works fine. (with Basic rules)

                                      2.0.2-RELEASE (amd64)  &  2.2.2-RELEASE (amd64)

                                      Always trying to learn!!

                                      1 Reply Last reply Reply Quote 0
                                      • ?
                                        Guest
                                        last edited by

                                        The updates are working fine now when I manually click update button, the version info states it is still package v 1.27 when it is actually 1.30.

                                        Also, there is still that issue with rules getting enabled after updates. This is starting to become a pain. I know that this was discussed before and not sure if there is a fix.

                                        I have a lot of rules that need to be disabled in certain categories I have to run, but everytime I get updates, it will enable the rules I disabled. Also it appears that the systems I am running are not getting updates automatically on the set time frame. I have a premium VRT license and currently running 8 PFsense boxes that all have the same issue.

                                        Thanks for any help.

                                        1 Reply Last reply Reply Quote 0
                                        • jimpJ
                                          jimp Rebel Alliance Developer Netgate
                                          last edited by

                                          @darklogic82:

                                          The updates are working fine now when I manually click update button, the version info states it is still package v 1.27 when it is actually 1.30.

                                          Also, there is still that issue with rules getting enabled after updates. This is starting to become a pain. I know that this was discussed before and not sure if there is a fix.

                                          I have a lot of rules that need to be disabled in certain categories I have to run, but everytime I get updates, it will enable the rules I disabled. Also it appears that the systems I am running are not getting updates automatically on the set time frame. I have a premium VRT license and currently running 8 PFsense boxes that all have the same issue.

                                          Thanks for any help.

                                          Those are separate issues from this thread, really. You might start a new thread for each of those issues separately, unless one already exists. I think there may already be some threads out there for the rules getting disabled.

                                          Hopefully the normal package maintainer returns soon and can work on this a bit. I stepped in to fix the updates mentioned in this thread at the request of a commercial support customer, I'd have to spend quite a bit more time looking at the package to even speculate on fixes for the other issues.

                                          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                                          Need help fast? Netgate Global Support!

                                          Do not Chat/PM for help!

                                          1 Reply Last reply Reply Quote 0
                                          • H
                                            Hugovsky
                                            last edited by

                                            Working good on 2.0. Thanks for the fix jimp.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.