Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort Won't Start After Upgrade

    Scheduled Pinned Locked Moved pfSense Packages
    301 Posts 64 Posters 216.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Cino
      last edited by

      @Ermal I noticed you added some code to allow inspecting gzipped http flows.. After updating the package i'm receiving this error:

      snort[1781]: FATAL ERROR: /usr/local/etc/snort/snort_39737_em3/snort.conf(171) => Enable 'extended_response_inspection' inspection before setting 'inspect_gzip'

      i removed the changes from my box and snort started again.

      doing some research, i add extended_response_inspection before the changes you change and snort started. Based on the docs, this is needed for the inspect_gzip setting

      
      			extended_response_inspection \
      			inspect_gzip \
      			normalize_utf \
      			unlimited_decompress \
      
      

      Reviewing the different settings, think it would make sense have them under Preprocessors: HTTP Inspect Settings. With all the different settings available for snort, I can see why it would almost be a full-time job to make everything configurable within pfSense.

      P.S I still can't clear the alert log. After clicking 'OK' to clear the log, nothing happens. At least i'm not being directed to a blank page now.

      1 Reply Last reply Reply Quote 0
      • E
        eri--
        last edited by

        Thanks Cino for the usual help.

        The alert mostly works when it does not work its mostly because of snort reloading or php doing something stupid though i have not investigated which is that does this.

        1 Reply Last reply Reply Quote 0
        • C
          Cino
          last edited by

          Anytime!

          Looks like someone figured out a fix for clearing the alert log. Take a look when you have time, http://redmine.pfsense.org/issues/1765

          1 Reply Last reply Reply Quote 0
          • E
            eri--
            last edited by

            I just pushed the fixes for the alert.
            Test it out.

            1 Reply Last reply Reply Quote 0
            • C
              Cino
              last edited by

              tested and confirm it is working.. Thanks again

              1 Reply Last reply Reply Quote 0
              • B
                bdwyer
                last edited by

                How did you manage to update Snort with that fix?  Is it in a new ISO or must I place the new snort_alerts.php there manually?

                CCNP, MCITP

                Intel Atom N550 - 2gb DDR3
                Jetway NC9C-550-LF
                Antec ISK 300-150
                HP ProCurve 1810-24
                Cisco 1841 & 2821, Cisco 3550 x3

                1 Reply Last reply Reply Quote 0
                • marcellocM
                  marcelloc
                  last edited by

                  @bdwyer:

                  How did you manage to update Snort with that fix?  Is it in a new ISO or must I place the new snort_alerts.php there manually?

                  Basically, when you see updates in forum and no change in package version, just reinstall(in this case snort package) to get latest files version.

                  Treinamentos de Elite: http://sys-squad.com

                  Help a community developer! ;D

                  1 Reply Last reply Reply Quote 0
                  • B
                    bdwyer
                    last edited by

                    Yes, I think that worked.  Thanks for filling me in.

                    CCNP, MCITP

                    Intel Atom N550 - 2gb DDR3
                    Jetway NC9C-550-LF
                    Antec ISK 300-150
                    HP ProCurve 1810-24
                    Cisco 1841 & 2821, Cisco 3550 x3

                    1 Reply Last reply Reply Quote 0
                    • X
                      xieliwei
                      last edited by

                      Sorry for reviving an old thread, but I've been having the Unknown output plugin: "alert_pf" problem on my AMD64 pfSense 2.0 install.

                      I originally thought it could be a package problem; but after a few updates and apparently no one else has this problem anymore, I suspect I'm missing something.

                      Can anyone clarify if "Block offenders" is working on AMD64?

                      If so, any clues about why mine doesn't work?

                      1 Reply Last reply Reply Quote 0
                      • marcellocM
                        marcelloc
                        last edited by

                        did you tried to uninstall / reinstall snort package?

                        Treinamentos de Elite: http://sys-squad.com

                        Help a community developer! ;D

                        1 Reply Last reply Reply Quote 0
                        • X
                          xieliwei
                          last edited by

                          Yes, every single time.
                          Just in case, I did it again. No luck.

                          Pretty sure my messing around caused this, anyone knows which library contains the alert_pf plugin?

                          1 Reply Last reply Reply Quote 0
                          • marcellocM
                            marcelloc
                            last edited by

                            Try to uninstall again, then go ti console and remove any snort package or dependencie left behind.
                            I think some post on this topic has a detailed info about this.

                            Treinamentos de Elite: http://sys-squad.com

                            Help a community developer! ;D

                            1 Reply Last reply Reply Quote 0
                            • C
                              cmb
                              last edited by

                              Locking this thread so it won't get hijacked over and over by numerous different issues, please start new threads instead.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.