Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SNORT - 2.9.1 pkg v. 2.0 - (http_inspect) - SID - 120:3:1

    Scheduled Pinned Locked Moved pfSense Packages
    13 Posts 9 Posters 15.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Cino
      last edited by

      its not an error but an alert

      1 Reply Last reply Reply Quote 0
      • B
        bdwyer
        last edited by

        Did you try this?  suppress gen_id 120, sig_id 3

        Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

        CCNP, MCITP

        Intel Atom N550 - 2gb DDR3
        Jetway NC9C-550-LF
        Antec ISK 300-150
        HP ProCurve 1810-24
        Cisco 1841 & 2821, Cisco 3550 x3

        1 Reply Last reply Reply Quote 0
        • T
          th3r3isnospoon
          last edited by

          @Cino:

          its not an error but an alert

          Yes, that is true.  However, about 80% of websites generate this alert.

          @bdwyer:

          Did you try this?  suppress gen_id 120, sig_id 3

          Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

          Hrmm… I just disabled HTTP inspect.  I then restarted the SNORT service and all is well.  I will try this and report back.

          At this point I am just wondering why exactly this is being triggered on almost every website I visit.

          Thanks,

          -th3r3isnospoon

          1 Reply Last reply Reply Quote 0
          • N
            NightHawk007
            last edited by

            @th3r3isnospoon:

            @Cino:

            its not an error but an alert

            Yes, that is true.  However, about 80% of websites generate this alert.

            @bdwyer:

            Did you try this?  suppress gen_id 120, sig_id 3

            Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

            I have the same problem and it is a big problem with web surfing blocks everything

            Hrmm… I just disabled HTTP inspect.  I then restarted the SNORT service and all is well.  I will try this and report back.

            At this point I am just wondering why exactly this is being triggered on almost every website I visit.

            Thanks,

            -th3r3isnospoon

            1 Reply Last reply Reply Quote 0
            • I
              ipv6kid
              last edited by

              I've created a video:
              http://www.youtube.com/watch?v=uQ7OrxtiAes

              1 Reply Last reply Reply Quote 0
              • B
                bdwyer
                last edited by

                @ipv6kid:

                I've created a video:
                http://www.youtube.com/watch?v=uQ7OrxtiAes

                Nice job.  Its kind of difficult to put into words that the interface must have the suppression list added to it and that simply creating the suppression list is not enough.

                CCNP, MCITP

                Intel Atom N550 - 2gb DDR3
                Jetway NC9C-550-LF
                Antec ISK 300-150
                HP ProCurve 1810-24
                Cisco 1841 & 2821, Cisco 3550 x3

                1 Reply Last reply Reply Quote 0
                • I
                  ipv6kid
                  last edited by

                  Thanks – Can we get a SOLVED tag put in the Subject?

                  1 Reply Last reply Reply Quote 0
                  • T
                    tim.mcmanus
                    last edited by

                    @ipv6kid:

                    I've created a video:
                    http://www.youtube.com/watch?v=uQ7OrxtiAes

                    Thank you!

                    1 Reply Last reply Reply Quote 0
                    • ?
                      A Former User
                      last edited by

                      @ipv6kid:

                      I've created a video:
                      http://www.youtube.com/watch?v=uQ7OrxtiAes

                      Thank You so Far so good !!!!! ^_^

                      1 Reply Last reply Reply Quote 0
                      • Y
                        yakupm
                        last edited by

                        @ipv6kid:

                        I've created a video:
                        http://www.youtube.com/watch?v=uQ7OrxtiAes

                        Well done - little good documentation exists for pfSense.  Your video explains one small but vital aspect of pfsense/snort.

                        Yak

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.