Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort Updating problems !!!

    Scheduled Pinned Locked Moved pfSense Packages
    72 Posts 27 Posters 36.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      djnicofun
      last edited by

      hello,

      I use Pfsense V1.2.3-RC1 , a have install package : Snort : 2.8.6 pkg v. 1.27

      i have find a bug , to update the rules the filename of the rules has change since : 10 junes 2010

      the file name is now :
      snortrules-snapshot-2860.tar.gz

      Example for snort 2.8.6.0:
            url = http://www.snort.org/pub-bin/oinkmaster.cgi/XXXXXXXXXXXXXX/snortrules-snapshot-2860.tar.gz

      Important Note from SNORT website:
      We are changing the way we publish rules. In June 2010 we stopped offering rules in the "snortrules-snapshot-CURRENT" format. Instead, rules are released for specific versions of Snort. You will be responsible for downloading the correct rules release for your version of Snort. The new versioning mechanism will require a four digit version in the file name.

      Please James can you update the package ?

      Best reagrds

      1 Reply Last reply Reply Quote 0
      • D
        djnicofun
        last edited by

        Where is the file : oinkmaster.conf  on pfsense vers: 1.2.21 ??

        1 Reply Last reply Reply Quote 0
        • R
          rnowotny
          last edited by

          Please check this post, it is a quick and dirty workaround until the new version is avail :

          http://forum.pfsense.org/index.php/topic,26382.msg139375.html#msg139375

          @djnicofun:

          hello,

          I use Pfsense V1.2.3-RC1 , a have install package : Snort : 2.8.6 pkg v. 1.27

          i have find a bug , to update the rules the filename of the rules has change since : 10 junes 2010

          the file name is now :
          snortrules-snapshot-2860.tar.gz

          Example for snort 2.8.6.0:
                url = http://www.snort.org/pub-bin/oinkmaster.cgi/XXXXXXXXXXXXXX/snortrules-snapshot-2860.tar.gz

          Important Note from SNORT website:
          We are changing the way we publish rules. In June 2010 we stopped offering rules in the "snortrules-snapshot-CURRENT" format. Instead, rules are released for specific versions of Snort. You will be responsible for downloading the correct rules release for your version of Snort. The new versioning mechanism will require a four digit version in the file name.

          Please James can you update the package ?

          Best reagrds

          1 Reply Last reply Reply Quote 0
          • D
            djnicofun
            last edited by

            hi,

            Ok thanck you, but i have already read this post, i would like know if an official update of this package will be done or not ?

            best regards.

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              Well they're tricky guys there at Sourcefire. There were a couple things wrong with the rule downloads:

              1. The URL changed.
              2. They now redirect you to an Amazon s3 URL to get the actual rules
              3. The Amazon url is HTTPS.

              So I fixed the URL, changed a redirect option, and I had to disable cURL's SSL validation, but now the rules download for me.

              The new package version is up now, give it a try and see if it works.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • C
                c0urier
                last edited by

                Giving it a try now. Will post back soon!

                Update:
                Seems to be working just fine - Rules updated and Snort running. Thanks jimp!!!

                pfsense: 2.1.5-RELEASE, AMD64
                Running on: MB/CPU: ASUS P8H77-I / Core i3-2120T | MEM: 8GB DDR3 | HDD: WD Blue 120GB 2.5" SATA | WAN/LAN: Fujitsu D2735-2 – Intel® chip 82576NS | WLAN: Realtek® 8111F PCIe | Connection: 1000/1000Mbit (Bredband2.com)
                [/U

                1 Reply Last reply Reply Quote 0
                • N
                  netmethods
                  last edited by

                  I tried it on all 3 of my pfSense boxes and is working fine. Thanks again Jim!

                  -Jason

                  2x Nexcom 1088n8 in HA config
                  2.4 GHz Quad Core / 4GB DDR2 / SATAII 160GB / 4x1GB Intel module

                  1 Reply Last reply Reply Quote 0
                  • D
                    DigitalJer
                    last edited by

                    Looking good here!

                    Many thanks…

                    –------------------------------------------------
                    2.4.3-RELEASE (amd64)
                    built on Mon Mar 26 18:02:04 CDT 2018
                    FreeBSD 11.1-RELEASE-p7
                    VM in ESXi 5.5
                    1 x 1000baseTX (WAN)
                    1 x 1000baseTX (LAN)

                    1 Reply Last reply Reply Quote 0
                    • ?
                      A Former User
                      last edited by

                      I uninstalled the old package and installed the new one and updated it no problem did a port scan test and all is working (fingers crossed) . ;D

                      1 Reply Last reply Reply Quote 0
                      • T
                        tester_02
                        last edited by

                        Question for those brave people that updated (no going back) :)
                        Premium rules or basic rules?

                        Hoping people have tested both…

                        1 Reply Last reply Reply Quote 0
                        • L
                          LostInIgnorance
                          last edited by

                          I used the subscribed rules and everything is working great over here

                          1 Reply Last reply Reply Quote 0
                          • D
                            DigitalJer
                            last edited by

                            Basic working fine for me.

                            –------------------------------------------------
                            2.4.3-RELEASE (amd64)
                            built on Mon Mar 26 18:02:04 CDT 2018
                            FreeBSD 11.1-RELEASE-p7
                            VM in ESXi 5.5
                            1 x 1000baseTX (WAN)
                            1 x 1000baseTX (LAN)

                            1 Reply Last reply Reply Quote 0
                            • T
                              tester_02
                              last edited by

                              Thanks for the feedback!  I'll give it a whirl…

                              1 Reply Last reply Reply Quote 0
                              • C
                                chowtamah
                                last edited by

                                Thanks Jimp.

                                Snort now updates and works fine. (with Basic rules)

                                2.0.2-RELEASE (amd64)  &  2.2.2-RELEASE (amd64)

                                Always trying to learn!!

                                1 Reply Last reply Reply Quote 0
                                • ?
                                  Guest
                                  last edited by

                                  The updates are working fine now when I manually click update button, the version info states it is still package v 1.27 when it is actually 1.30.

                                  Also, there is still that issue with rules getting enabled after updates. This is starting to become a pain. I know that this was discussed before and not sure if there is a fix.

                                  I have a lot of rules that need to be disabled in certain categories I have to run, but everytime I get updates, it will enable the rules I disabled. Also it appears that the systems I am running are not getting updates automatically on the set time frame. I have a premium VRT license and currently running 8 PFsense boxes that all have the same issue.

                                  Thanks for any help.

                                  1 Reply Last reply Reply Quote 0
                                  • jimpJ
                                    jimp Rebel Alliance Developer Netgate
                                    last edited by

                                    @darklogic82:

                                    The updates are working fine now when I manually click update button, the version info states it is still package v 1.27 when it is actually 1.30.

                                    Also, there is still that issue with rules getting enabled after updates. This is starting to become a pain. I know that this was discussed before and not sure if there is a fix.

                                    I have a lot of rules that need to be disabled in certain categories I have to run, but everytime I get updates, it will enable the rules I disabled. Also it appears that the systems I am running are not getting updates automatically on the set time frame. I have a premium VRT license and currently running 8 PFsense boxes that all have the same issue.

                                    Thanks for any help.

                                    Those are separate issues from this thread, really. You might start a new thread for each of those issues separately, unless one already exists. I think there may already be some threads out there for the rules getting disabled.

                                    Hopefully the normal package maintainer returns soon and can work on this a bit. I stepped in to fix the updates mentioned in this thread at the request of a commercial support customer, I'd have to spend quite a bit more time looking at the package to even speculate on fixes for the other issues.

                                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                                    Need help fast? Netgate Global Support!

                                    Do not Chat/PM for help!

                                    1 Reply Last reply Reply Quote 0
                                    • H
                                      Hugovsky
                                      last edited by

                                      Working good on 2.0. Thanks for the fix jimp.

                                      1 Reply Last reply Reply Quote 0
                                      • T
                                        tehtrk
                                        last edited by

                                        It works great.  ;D

                                        You da man, JimP

                                        1 Reply Last reply Reply Quote 0
                                        • D
                                          dszp
                                          last edited by

                                          I will try this soon, thanks JimP! The man who "wrote the book" wrote the snort fix :-) And probably quite a bit of pfSense itself, though I don't know the full extent of his contributions :-)

                                          David Szpunar

                                          1 Reply Last reply Reply Quote 0
                                          • N
                                            nocer
                                            last edited by

                                            thanks jimp, fix that you provided makes my daily update jobs very easy, because I have been fetch/extract/install every single day by hand which is, annoying.

                                            now that my concern is how you can conpromise longer i/f names that looks like 2.0 specific issue which won't snort from starting at the booting, or any other attempt. i tricked some diy for i/f naming but none of those were permanent fix, system will assign a new name, everytime reload the box.

                                            any thoughts and ideas appreciated.

                                            cheers,

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.