Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort issue with cat. emerging-netbios.rules

    Scheduled Pinned Locked Moved pfSense Packages
    2 Posts 1 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jmack
      last edited by

      Hi,

      What might be the problem with categorie "emerging-netbios.rules"? I narrowed down that WITH this cat. enabled Snort on my Dell server won't start whatsoever…. Even when disabling 10 other categories won't help.

      Server:

      • Dell T110 4Gb i3 CPU 530 / Pfsense 1.2.3 / 1+4 Intel Gbit-nic's  (lan,wan,DMZ1,DMZ2,WLAN)

      PF Packages:
      Backup, cron, dashboard, OpenVPNstatus, and Snort 2.8.6.1 pkg v. 1.34/1.35? (newest)

      Snort config:

      • Installed Emergingthreats rules and Oinkmaster code
      • just one interface added to snort, WAN with ACS performance
      • added all categories, except emerging-netbios.rules.
      • All Preprocessors enabled
      • Servers and barnyard is empty/disabled (for now)
      • Suppress is empty
      • INSTALLED SIGNATURE RULESET
          SNORT.ORG >>>  N/A
          EMERGINGTHREATS.NET >>>  N/A
          PFSENSE.ORG >>>  102

      (Some days back I had the first 2 signatures as well...some hashcode and a 4-digit-no.)

      1 Reply Last reply Reply Quote 0
      • J Offline
        jmack
        last edited by

        Mmm… might has to do with this:... (???)
        http://redmine.pfsense.org/projects/pfsense-packages/repository/revisions/e4352e9638d14a3bf2a36a71b1df6376b2ce703c

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.