Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort Rules update Broken

    pfSense Packages
    3
    4
    2.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Skirmish
      last edited by

      I'm having trouble using the update rules for snort. When I do a manual update the updater gets through a few small files to then while downloading the larger rules package it sticks and the status bar stops moving. I've set the auto-update to download every 6hrs but that doesn't do anything either. Every time I go to the update rules tab in snort it gives me a warning that /usr/local/etc/snort/rules is empty.

      I've manually downloaded the snort rules to an FTP server then downloaded & unpacked it into /usr/local/etc/snort/rules and the update rules tab has stopped complaining but I'm not sure if

      1. The rules have been installed correctly into the right directory
      2. The rules will ever be updated automatically

      PFSense 1.2.3-RELEASE
      Snort 2.8.6 pkg v. 1.30

      1 Reply Last reply Reply Quote 0
      • D
        DigitalJer
        last edited by

        Manual update:  http://forum.pfsense.org/index.php/topic,26382.msg137567.html#msg137567

        …and the update feature of Snort is discussed heavily in that thread - all you need to know should be in there.

        –------------------------------------------------
        2.4.3-RELEASE (amd64)
        built on Mon Mar 26 18:02:04 CDT 2018
        FreeBSD 11.1-RELEASE-p7
        VM in ESXi 5.5
        1 x 1000baseTX (WAN)
        1 x 1000baseTX (LAN)

        1 Reply Last reply Reply Quote 0
        • jnorellJ
          jnorell
          last edited by

          Your problem is with v1.30, and isn't the same as the recent broken update issue.  From the "things to try" camp, you might remove the snort package and reinstall it (with or without saving your config).  I was using v1.27, updated to v1.30 and it's working fine for me.

          1 Reply Last reply Reply Quote 0
          • S
            Skirmish
            last edited by

            Thanks guys - Manual update worked in the end, auto still not happening up until now. Maybe now that there's a rule set in place the auto updates will roll in? We'll see in ~6 hrs I guess.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.