Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort package on 64 doesn't work

    Scheduled Pinned Locked Moved pfSense Packages
    55 Posts 16 Posters 20.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      seattle-it
      last edited by

      @VeGeTa-X:

      I ran your command " /usr/local/bin/snort -u snort -g snort -v -l /var/log/snort –pid-path /var/log/snort/run -c /usr/local/etc/snort/snort_61267_re0/snort.conf -i re0 " and I received the error message below

      /libexec/ld-elf.so.1: Shared object "libpcap.so.1" not found, required by "snort"

      make sure /usr/lib/libpcap.so is there then run..

      
      ln -s /usr/lib/libpcap.so /usr/lib/libpcap.so.1
      
      

      And try again

      My tech blog - seattleit.net/blog

      1 Reply Last reply Reply Quote 0
      • V
        VeGeTa-X
        last edited by

        thx linking both files worked i just had to turn off block offender and restart and it worked. Thx again for your help

        1 Reply Last reply Reply Quote 0
        • V
          VeGeTa-X
          last edited by

          I have one more question when I enable block offenders snort does not work and when I disable it snort works.  I found the link below saying that snort package is missing some kind of spoink code?

          http://redmine.pfsense.org/issues/1753

          1 Reply Last reply Reply Quote 0
          • I
            Ibor Daru
            last edited by

            @seattle-it:

            @VeGeTa-X:

            I ran your command " /usr/local/bin/snort -u snort -g snort -v -l /var/log/snort –pid-path /var/log/snort/run -c /usr/local/etc/snort/snort_61267_re0/snort.conf -i re0 " and I received the error message below

            /libexec/ld-elf.so.1: Shared object "libpcap.so.1" not found, required by "snort"

            make sure /usr/lib/libpcap.so is there then run..

            
            ln -s /usr/lib/libpcap.so /usr/lib/libpcap.so.1
            
            

            And try again

            Can't thank you enough! Snort is working again after so long, such an easy fix!

            1 Reply Last reply Reply Quote 0
            • V
              VeGeTa-X
              last edited by

              it seems a bit weird  snort is running but I am not receiving any alerts

              1 Reply Last reply Reply Quote 0
              • C
                Cino
                last edited by

                are your preprocessors turned on? goto https://www.grc.com/x/ne.dll?bh0bkyd2 to test snort… you should get a scan alert

                1 Reply Last reply Reply Quote 0
                • V
                  VeGeTa-X
                  last edited by

                  yes all options are turned on for preprocessors and did a all port scan on the site below and no alerts.

                  1 Reply Last reply Reply Quote 0
                  • C
                    Cino
                    last edited by

                    i have no idea ???  It worked for me last weekend… Are your running 2.0RC3 or 2.1-Dev?

                    1 Reply Last reply Reply Quote 0
                    • V
                      VeGeTa-X
                      last edited by

                      I am running 2.0rc3 64bit

                      1 Reply Last reply Reply Quote 0
                      • G
                        Gloom
                        last edited by

                        @VeGeTa-X:

                        I have one more question when I enable block offenders snort does not work and when I disable it snort works.  I found the link below saying that snort package is missing some kind of spoink code?

                        http://redmine.pfsense.org/issues/1753

                        spoink is an Open BSD output plugin that adds the offending host to the block list in snort. I was always under the impression that pfsense used snort2c to do that job. Seems I was wrong.

                        Never underestimate the power of human stupidity

                        1 Reply Last reply Reply Quote 0
                        • C
                          Cino
                          last edited by

                          @VeGeTa-X:

                          I am running 2.0rc3 64bit

                          i'll have to start a vm for 2.0rc3… I tried 2.1 Dev last weekend and it worked for me

                          1 Reply Last reply Reply Quote 0
                          • I
                            Ibor Daru
                            last edited by

                            @Cino:

                            @VeGeTa-X:

                            I am running 2.0rc3 64bit

                            i'll have to start a vm for 2.0rc3… I tried 2.1 Dev last weekend and it worked for me

                            Running 2.0-RC3 (amd64) built on Sat Aug 6 23:18:46 EDT 2011. Checked "Send alerts to main System logs". I'm getting alerts within the Alerts tab as well as the main system logs.

                            1 Reply Last reply Reply Quote 0
                            • C
                              Cino
                              last edited by

                              @Ibor:

                              @Cino:

                              @VeGeTa-X:

                              I am running 2.0rc3 64bit

                              i'll have to start a vm for 2.0rc3… I tried 2.1 Dev last weekend and it worked for me

                              Running 2.0-RC3 (amd64) built on Sat Aug 6 23:18:46 EDT 2011. Checked "Send alerts to main System logs". I'm getting alerts within the Alerts tab as well as the main system logs.

                              So it is working on 2.0RC3..Good to know

                              1 Reply Last reply Reply Quote 0
                              • A
                                asterix
                                last edited by

                                Can a couple of more folks confirm Snort works on latest amd64 2.0 RC3 snapshots? I tried it on earlier this week and it was not working. Had done clean installs a few times but was never successful to get Snort running. Now on 32-bit 2.0 RC3 as Snort is kinda broken even on 1.2.3 with Snort.org rules not updating. Not a happy camper !!

                                1 Reply Last reply Reply Quote 0
                                • C
                                  Cino
                                  last edited by

                                  @asterix:

                                  Can a couple of more folks confirm Snort works on latest amd64 2.0 RC3 snapshots? I tried it on earlier this week and it was not working. Had done clean installs a few times but was never successful to get Snort running. Now on 32-bit 2.0 RC3 as Snort is kinda broken even on 1.2.3 with Snort.org rules not updating. Not a happy camper !!

                                  Its works on 2.0RC3 i386… 2 bugs that I know of, Barnyard2 and you can't clear the alerts but you can clear the block list... There are post for a workaround on barnyard2

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    asterix
                                    last edited by

                                    amd64?

                                    1 Reply Last reply Reply Quote 0
                                    • I
                                      Ibor Daru
                                      last edited by

                                      @Cino:

                                      @Ibor:

                                      @Cino:

                                      @VeGeTa-X:

                                      I am running 2.0rc3 64bit

                                      i'll have to start a vm for 2.0rc3… I tried 2.1 Dev last weekend and it worked for me

                                      Running 2.0-RC3 (amd64) built on Sat Aug 6 23:18:46 EDT 2011. Checked "Send alerts to main System logs". I'm getting alerts within the Alerts tab as well as the main system logs.

                                      So it is working on 2.0RC3..Good to know

                                      BUT only after entering/executing the following code!! Without it, Snort will not work!

                                      
                                      ln -s /usr/lib/libpcap.so /usr/lib/libpcap.so.1
                                      
                                      
                                      1 Reply Last reply Reply Quote 0
                                      • C
                                        Cino
                                        last edited by

                                        @Ibor:

                                        @Cino:

                                        @Ibor:

                                        @Cino:

                                        @VeGeTa-X:

                                        I am running 2.0rc3 64bit

                                        i'll have to start a vm for 2.0rc3… I tried 2.1 Dev last weekend and it worked for me

                                        Running 2.0-RC3 (amd64) built on Sat Aug 6 23:18:46 EDT 2011. Checked "Send alerts to main System logs". I'm getting alerts within the Alerts tab as well as the main system logs.

                                        So it is working on 2.0RC3..Good to know

                                        BUT only after entering/executing the following code!! Without it, Snort will not work!

                                        
                                        ln -s /usr/lib/libpcap.so /usr/lib/libpcap.so.1
                                        
                                        

                                        I wonder if its because of all the packages i have install, maybe one of them ran that command for me…

                                        1 Reply Last reply Reply Quote 0
                                        • A
                                          asterix
                                          last edited by

                                          So basically snort on amd64 is still broken.

                                          1 Reply Last reply Reply Quote 0
                                          • C
                                            Cino
                                            last edited by

                                            @asterix:

                                            So basically snort on amd64 is still broken.

                                            well if it runs after running a command or two, it wouldn't be broken then! Any why not just run i386? Unless your pumping heavy traffic thru the box and need a lot of memory, I see no benefit running AMD64.

                                            I hate to say this but if your so bent out of shape for snort, then go install another fw distro and deal with their bloatware instead of whining on every snort thread that its not working. There are tickets opened on the issue and the dev's will get to them when they can. You can always donate money to help push it along if you like.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.