Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SNORT - 2.9.1 pkg v. 2.0 - (http_inspect) - SID - 120:3:1

    Scheduled Pinned Locked Moved pfSense Packages
    13 Posts 9 Posters 15.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      th3r3isnospoon
      last edited by

      @RonpfS:

      http://forum.pfsense.org/index.php/topic,41533.msg220890.html#msg220890

      Thanks for the link.

      I actually saw that thread and read through it.  I was just able to get the -1 to work.  However, I would like this to be at 0.  I had it at 0 on the last version of the SNORT package and I never had this error before.  Just curious why this happened after the upgrade.  Was this not fully working before?

      Thanks,

      -th3r3isnospoon

      1 Reply Last reply Reply Quote 0
      • C
        Cino
        last edited by

        its not an error but an alert

        1 Reply Last reply Reply Quote 0
        • B
          bdwyer
          last edited by

          Did you try this?  suppress gen_id 120, sig_id 3

          Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

          CCNP, MCITP

          Intel Atom N550 - 2gb DDR3
          Jetway NC9C-550-LF
          Antec ISK 300-150
          HP ProCurve 1810-24
          Cisco 1841 & 2821, Cisco 3550 x3

          1 Reply Last reply Reply Quote 0
          • T
            th3r3isnospoon
            last edited by

            @Cino:

            its not an error but an alert

            Yes, that is true.  However, about 80% of websites generate this alert.

            @bdwyer:

            Did you try this?  suppress gen_id 120, sig_id 3

            Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

            Hrmm… I just disabled HTTP inspect.  I then restarted the SNORT service and all is well.  I will try this and report back.

            At this point I am just wondering why exactly this is being triggered on almost every website I visit.

            Thanks,

            -th3r3isnospoon

            1 Reply Last reply Reply Quote 0
            • N
              NightHawk007
              last edited by

              @th3r3isnospoon:

              @Cino:

              its not an error but an alert

              Yes, that is true.  However, about 80% of websites generate this alert.

              @bdwyer:

              Did you try this?  suppress gen_id 120, sig_id 3

              Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

              I have the same problem and it is a big problem with web surfing blocks everything

              Hrmm… I just disabled HTTP inspect.  I then restarted the SNORT service and all is well.  I will try this and report back.

              At this point I am just wondering why exactly this is being triggered on almost every website I visit.

              Thanks,

              -th3r3isnospoon

              1 Reply Last reply Reply Quote 0
              • I
                ipv6kid
                last edited by

                I've created a video:
                http://www.youtube.com/watch?v=uQ7OrxtiAes

                1 Reply Last reply Reply Quote 0
                • B
                  bdwyer
                  last edited by

                  @ipv6kid:

                  I've created a video:
                  http://www.youtube.com/watch?v=uQ7OrxtiAes

                  Nice job.  Its kind of difficult to put into words that the interface must have the suppression list added to it and that simply creating the suppression list is not enough.

                  CCNP, MCITP

                  Intel Atom N550 - 2gb DDR3
                  Jetway NC9C-550-LF
                  Antec ISK 300-150
                  HP ProCurve 1810-24
                  Cisco 1841 & 2821, Cisco 3550 x3

                  1 Reply Last reply Reply Quote 0
                  • I
                    ipv6kid
                    last edited by

                    Thanks – Can we get a SOLVED tag put in the Subject?

                    1 Reply Last reply Reply Quote 0
                    • T
                      tim.mcmanus
                      last edited by

                      @ipv6kid:

                      I've created a video:
                      http://www.youtube.com/watch?v=uQ7OrxtiAes

                      Thank you!

                      1 Reply Last reply Reply Quote 0
                      • ?
                        A Former User
                        last edited by

                        @ipv6kid:

                        I've created a video:
                        http://www.youtube.com/watch?v=uQ7OrxtiAes

                        Thank You so Far so good !!!!! ^_^

                        1 Reply Last reply Reply Quote 0
                        • Y
                          yakupm
                          last edited by

                          @ipv6kid:

                          I've created a video:
                          http://www.youtube.com/watch?v=uQ7OrxtiAes

                          Well done - little good documentation exists for pfSense.  Your video explains one small but vital aspect of pfsense/snort.

                          Yak

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.