Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid - Operation Not Permitted error

    pfSense Packages
    2
    4
    3.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      miles267
      last edited by

      I recently noticed that Snort was returning Operation Not Permitted errors for certain web sites embedded within other sites OR when attempting to go to other websites (www.dyson.com for example).  Short of disabling any Snort category containing "web-client" within the title, is there a better way to address this issue?  Seems like I'm disabling 100% of snort's web client protection when I may only need to disable a specific Snort rule within the category itself.

      Has anyone figured out how to determine specifically which rule is the problem and how to disable only that one to address the issue?

      1 Reply Last reply Reply Quote 0
      • marcellocM
        marcelloc
        last edited by

        It will be on snort logs, take a look on any http inspect forum topic to see how to do this.

        One how to I know is this video tutorial.

        https://www.youtube.com/watch?v=uQ7OrxtiAes

        Treinamentos de Elite: http://sys-squad.com

        Help a community developer! ;D

        1 Reply Last reply Reply Quote 0
        • M
          miles267
          last edited by

          Thank you.  I've followed this great YouTube tutorial. Was very helpful.  Isn't always easy to tell exactly which alert corresponds with which action but I usually clear all Snort alerts and attempt to reproduce the issue to see whether it then shows up in the logs.

          Also, is it me or does it take a while after restarting Snort for it to load up and load all categories/rules?

          1 Reply Last reply Reply Quote 0
          • marcellocM
            marcelloc
            last edited by

            Not sure. I do not change snort rules that often.

            Treinamentos de Elite: http://sys-squad.com

            Help a community developer! ;D

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.