Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SNORT - 2.9.1 pkg v. 2.0 - (http_inspect) - SID - 120:3:1

    Scheduled Pinned Locked Moved pfSense Packages
    13 Posts 9 Posters 15.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RonpfSR
      RonpfS
      last edited by

      http://forum.pfsense.org/index.php/topic,41533.msg220890.html#msg220890

      2.4.5-RELEASE-p1 (amd64)
      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

      1 Reply Last reply Reply Quote 0
      • T
        th3r3isnospoon
        last edited by

        @RonpfS:

        http://forum.pfsense.org/index.php/topic,41533.msg220890.html#msg220890

        Thanks for the link.

        I actually saw that thread and read through it.  I was just able to get the -1 to work.  However, I would like this to be at 0.  I had it at 0 on the last version of the SNORT package and I never had this error before.  Just curious why this happened after the upgrade.  Was this not fully working before?

        Thanks,

        -th3r3isnospoon

        1 Reply Last reply Reply Quote 0
        • C
          Cino
          last edited by

          its not an error but an alert

          1 Reply Last reply Reply Quote 0
          • B
            bdwyer
            last edited by

            Did you try this?  suppress gen_id 120, sig_id 3

            Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

            CCNP, MCITP

            Intel Atom N550 - 2gb DDR3
            Jetway NC9C-550-LF
            Antec ISK 300-150
            HP ProCurve 1810-24
            Cisco 1841 & 2821, Cisco 3550 x3

            1 Reply Last reply Reply Quote 0
            • T
              th3r3isnospoon
              last edited by

              @Cino:

              its not an error but an alert

              Yes, that is true.  However, about 80% of websites generate this alert.

              @bdwyer:

              Did you try this?  suppress gen_id 120, sig_id 3

              Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

              Hrmm… I just disabled HTTP inspect.  I then restarted the SNORT service and all is well.  I will try this and report back.

              At this point I am just wondering why exactly this is being triggered on almost every website I visit.

              Thanks,

              -th3r3isnospoon

              1 Reply Last reply Reply Quote 0
              • N
                NightHawk007
                last edited by

                @th3r3isnospoon:

                @Cino:

                its not an error but an alert

                Yes, that is true.  However, about 80% of websites generate this alert.

                @bdwyer:

                Did you try this?  suppress gen_id 120, sig_id 3

                Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

                I have the same problem and it is a big problem with web surfing blocks everything

                Hrmm… I just disabled HTTP inspect.  I then restarted the SNORT service and all is well.  I will try this and report back.

                At this point I am just wondering why exactly this is being triggered on almost every website I visit.

                Thanks,

                -th3r3isnospoon

                1 Reply Last reply Reply Quote 0
                • I
                  ipv6kid
                  last edited by

                  I've created a video:
                  http://www.youtube.com/watch?v=uQ7OrxtiAes

                  1 Reply Last reply Reply Quote 0
                  • B
                    bdwyer
                    last edited by

                    @ipv6kid:

                    I've created a video:
                    http://www.youtube.com/watch?v=uQ7OrxtiAes

                    Nice job.  Its kind of difficult to put into words that the interface must have the suppression list added to it and that simply creating the suppression list is not enough.

                    CCNP, MCITP

                    Intel Atom N550 - 2gb DDR3
                    Jetway NC9C-550-LF
                    Antec ISK 300-150
                    HP ProCurve 1810-24
                    Cisco 1841 & 2821, Cisco 3550 x3

                    1 Reply Last reply Reply Quote 0
                    • I
                      ipv6kid
                      last edited by

                      Thanks – Can we get a SOLVED tag put in the Subject?

                      1 Reply Last reply Reply Quote 0
                      • T
                        tim.mcmanus
                        last edited by

                        @ipv6kid:

                        I've created a video:
                        http://www.youtube.com/watch?v=uQ7OrxtiAes

                        Thank you!

                        1 Reply Last reply Reply Quote 0
                        • ?
                          A Former User
                          last edited by

                          @ipv6kid:

                          I've created a video:
                          http://www.youtube.com/watch?v=uQ7OrxtiAes

                          Thank You so Far so good !!!!! ^_^

                          1 Reply Last reply Reply Quote 0
                          • Y
                            yakupm
                            last edited by

                            @ipv6kid:

                            I've created a video:
                            http://www.youtube.com/watch?v=uQ7OrxtiAes

                            Well done - little good documentation exists for pfSense.  Your video explains one small but vital aspect of pfsense/snort.

                            Yak

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.