Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort not working?

    Scheduled Pinned Locked Moved pfSense Packages
    12 Posts 5 Posters 6.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      Bai Shen
      last edited by

      @LostInIgnorance:

      What interface is it running on?

      WAN

      1 Reply Last reply Reply Quote 0
      • L
        LostInIgnorance
        last edited by

        Can you give a bit of info about your network setup? (asci/paint diagram would be nice)

        1 Reply Last reply Reply Quote 0
        • B
          Bai Shen
          last edited by

          Not to be difficult, but what does that have to do with snort picking up things from the internet?

          1 Reply Last reply Reply Quote 0
          • L
            LostInIgnorance
            last edited by

            If you have something before the pfsense, sometimes the modems associated with dsl/cable have firewalls naturally enabled on them.

            1 Reply Last reply Reply Quote 0
            • B
              Bai Shen
              last edited by

              @LostInIgnorance:

              If you have something before the pfsense, sometimes the modems associated with dsl/cable have firewalls naturally enabled on them.

              Just the same Moto 6120 I've been running previously.

              1 Reply Last reply Reply Quote 0
              • M
                mantic
                last edited by

                I have the same issue… I may just build the damn thing by hand... it seems that it doesn't pick up EXTERNAL and INTERNAL net...

                1 Reply Last reply Reply Quote 0
                • J
                  jamesdean
                  last edited by

                  @mantic:

                  I have the same issue… I may just build the damn thing by hand... it seems that it doesn't pick up EXTERNAL and INTERNAL net...

                  @mantic

                  Do us a favor.

                  Post you system spec, network map and any setting that might affect snort.

                  Rob

                  1 Reply Last reply Reply Quote 0
                  • B
                    Bai Shen
                    last edited by

                    So, I went to GRC and did a port scan on my ip.  Still nothing from Snort.  I'm beginning to wonder if it's even running.

                    What can I look at in order to tell if things are working correctly?

                    1 Reply Last reply Reply Quote 0
                    • _
                      _igor_
                      last edited by

                      when snort starts up, it fills the whole systemlog with messages. The last ones should be like this:

                      snort[62829]: Snort initialization completed successfully (pid=62829)
                      Mar 25 00:02:18	snort[62829]: Snort initialization completed successfully (pid=62829)
                      Mar 25 00:02:18	snort[62829]: --== Initialization Complete ==--
                      Mar 25 00:02:18	snort[62829]: --== Initialization Complete ==--
                      
                      1 Reply Last reply Reply Quote 0
                      • B
                        Bai Shen
                        last edited by

                        Yeah, it turned out I had to turn on the preprocessors.

                        BTW, it lists an option for collecting performance statistics, but I couldn't find where they're collected.  Any ideas?

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.