Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort Won't Start After Upgrade

    Scheduled Pinned Locked Moved pfSense Packages
    301 Posts 64 Posters 225.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      breusshe
      last edited by

      I personally consider it a bug since you don't normally think of your home net as your WAN interface.  I don't know how pfSense feels about that, which is what will ultimately decide if this is a "bug" or "feature".

      1 Reply Last reply Reply Quote 0
      • C
        Cino
        last edited by

        @Ermal I noticed you added some code to allow inspecting gzipped http flows.. After updating the package i'm receiving this error:

        snort[1781]: FATAL ERROR: /usr/local/etc/snort/snort_39737_em3/snort.conf(171) => Enable 'extended_response_inspection' inspection before setting 'inspect_gzip'

        i removed the changes from my box and snort started again.

        doing some research, i add extended_response_inspection before the changes you change and snort started. Based on the docs, this is needed for the inspect_gzip setting

        
        			extended_response_inspection \
        			inspect_gzip \
        			normalize_utf \
        			unlimited_decompress \
        
        

        Reviewing the different settings, think it would make sense have them under Preprocessors: HTTP Inspect Settings. With all the different settings available for snort, I can see why it would almost be a full-time job to make everything configurable within pfSense.

        P.S I still can't clear the alert log. After clicking 'OK' to clear the log, nothing happens. At least i'm not being directed to a blank page now.

        1 Reply Last reply Reply Quote 0
        • E
          eri--
          last edited by

          Thanks Cino for the usual help.

          The alert mostly works when it does not work its mostly because of snort reloading or php doing something stupid though i have not investigated which is that does this.

          1 Reply Last reply Reply Quote 0
          • C
            Cino
            last edited by

            Anytime!

            Looks like someone figured out a fix for clearing the alert log. Take a look when you have time, http://redmine.pfsense.org/issues/1765

            1 Reply Last reply Reply Quote 0
            • E
              eri--
              last edited by

              I just pushed the fixes for the alert.
              Test it out.

              1 Reply Last reply Reply Quote 0
              • C
                Cino
                last edited by

                tested and confirm it is working.. Thanks again

                1 Reply Last reply Reply Quote 0
                • B
                  bdwyer
                  last edited by

                  How did you manage to update Snort with that fix?  Is it in a new ISO or must I place the new snort_alerts.php there manually?

                  CCNP, MCITP

                  Intel Atom N550 - 2gb DDR3
                  Jetway NC9C-550-LF
                  Antec ISK 300-150
                  HP ProCurve 1810-24
                  Cisco 1841 & 2821, Cisco 3550 x3

                  1 Reply Last reply Reply Quote 0
                  • marcellocM
                    marcelloc
                    last edited by

                    @bdwyer:

                    How did you manage to update Snort with that fix?  Is it in a new ISO or must I place the new snort_alerts.php there manually?

                    Basically, when you see updates in forum and no change in package version, just reinstall(in this case snort package) to get latest files version.

                    Treinamentos de Elite: http://sys-squad.com

                    Help a community developer! ;D

                    1 Reply Last reply Reply Quote 0
                    • B
                      bdwyer
                      last edited by

                      Yes, I think that worked.  Thanks for filling me in.

                      CCNP, MCITP

                      Intel Atom N550 - 2gb DDR3
                      Jetway NC9C-550-LF
                      Antec ISK 300-150
                      HP ProCurve 1810-24
                      Cisco 1841 & 2821, Cisco 3550 x3

                      1 Reply Last reply Reply Quote 0
                      • X
                        xieliwei
                        last edited by

                        Sorry for reviving an old thread, but I've been having the Unknown output plugin: "alert_pf" problem on my AMD64 pfSense 2.0 install.

                        I originally thought it could be a package problem; but after a few updates and apparently no one else has this problem anymore, I suspect I'm missing something.

                        Can anyone clarify if "Block offenders" is working on AMD64?

                        If so, any clues about why mine doesn't work?

                        1 Reply Last reply Reply Quote 0
                        • marcellocM
                          marcelloc
                          last edited by

                          did you tried to uninstall / reinstall snort package?

                          Treinamentos de Elite: http://sys-squad.com

                          Help a community developer! ;D

                          1 Reply Last reply Reply Quote 0
                          • X
                            xieliwei
                            last edited by

                            Yes, every single time.
                            Just in case, I did it again. No luck.

                            Pretty sure my messing around caused this, anyone knows which library contains the alert_pf plugin?

                            1 Reply Last reply Reply Quote 0
                            • marcellocM
                              marcelloc
                              last edited by

                              Try to uninstall again, then go ti console and remove any snort package or dependencie left behind.
                              I think some post on this topic has a detailed info about this.

                              Treinamentos de Elite: http://sys-squad.com

                              Help a community developer! ;D

                              1 Reply Last reply Reply Quote 0
                              • C
                                cmb
                                last edited by

                                Locking this thread so it won't get hijacked over and over by numerous different issues, please start new threads instead.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.