Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort 2.9.2.3 pkg v. 2.3.0 Issue Thread

    Scheduled Pinned Locked Moved pfSense Packages
    22 Posts 8 Posters 5.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Cino
      last edited by

      That did it for barnyard2! Able to stop and start via Snort GUI and Services. Haven't tried a reboot yet.. But since Services uses /usr/local/etc/rc.d/snort.sh as well, I would think it would work also.

      I'll have to do a deep drive later but I think its all small stuff..but..

      I see now on the Snort Interface page, Barnyard2 is shaded Red when its turn off and White when its enabled. Could it be Green when its enabled? Also, can we do the same for the Interface also? Don't know if it should go under 'If' or 'Snort' columns. It was under 'If' but to keep it the same as barnyard2, i would put it under 'Snort'…idk.. you decide on what is easier and looks more functionally.

      thankyou for getting barnyard2 working correctly..

      1 Reply Last reply Reply Quote 0
      • D
        digdug3
        last edited by

        Tested upgrading from v2.2.4 to v2.3.0 on AMD64 works without any problems.
        As soon as everything works I will upgrade my production machine from Snort 2.9.1 pkg v. 2.1.1 (AMD64) to this version.

        As Cino said, I too would prefer green/red colors, just like the stop and play buttons.

        1 Reply Last reply Reply Quote 0
        • 1
          10101000
          last edited by

          Aside from the problems listed in the original post, version 2.3.0 is running smoothly for myself. For a quick "blocked alerts description" fix see post 274405.

          Thanks for the hard work Ermal!

          1 Reply Last reply Reply Quote 0
          • C
            Cino
            last edited by

            I've crossed out what has been resolved on the first post and added some…

            @10101000 your patch worked for me.. thank you

            1 Reply Last reply Reply Quote 0
            • D
              digdug3
              last edited by

              Cron Job Issue:
              After every install/reinstall, you have to save the Global Settings and Interface page (with Blocked Enabled) for the Cron job to be created. Is there a way to fix it so the package does a check automatically to see if that setting is set?

              Maybe -if- the Global settings was saved, after an update of the package, automatically updates the rules before starting Snort.

              1 Reply Last reply Reply Quote 0
              • F
                Fesoj
                last edited by

                If you have more than a single snort interface running, only the message of the 1st instance can be cleared (already described somewhere else). I noticed some code changes in snort_alert.php, but the code does not work correctly.

                It looks as if the state of the settings are not properly maintained. $instanceid does receive the correct value, but after hitting the clear-button the value is back to its default value 0 before the clear action gets executed, so other interfaces never get a chance to get rid of their messages (to study this behavior I am dumping some diagnostics into a temporary file).

                Not being familiar with php, I'd say the problem is due to the way php scripts get initialized and executed and after hitting a button like "Clear", your're essentially back to a fresh page. With the proper knowledge this can probably be fixed easily.

                1 Reply Last reply Reply Quote 0
                • F
                  Fesoj
                  last edited by

                  With this version the Emerging Threats rules are working for me, but the Snort rules don't.

                  I did some tests with the p2p rules, and the Snort rules neither generated alerts nor did blocking work.

                  1 Reply Last reply Reply Quote 0
                  • E
                    eri--
                    last edited by

                    In 2.4.0 all these issues should be solved apart the colors in the interface page

                    1 Reply Last reply Reply Quote 0
                    • F
                      Fesoj
                      last edited by

                      See http://forum.pfsense.org/index.php/topic,51375.msg274556.html#msg274556

                      1 Reply Last reply Reply Quote 0
                      • C
                        Cino
                        last edited by

                        on and off snort does quits when it tries to block an IP

                        
                        Jul 11 14:24:32 	snort[22453]: FATAL ERROR: s2c_pf_block() => ioctl() DIOCRADDADDRS: Inappropriate ioctl for device
                        Jul 11 14:24:32 	snort[22453]: FATAL ERROR: s2c_pf_block() => ioctl() DIOCRADDADDRS: Inappropriate ioctl for device
                        
                        
                        1 Reply Last reply Reply Quote 0
                        • E
                          eri--
                          last edited by

                          That is rather awkward.
                          Can you identify the line that caused that? In alerts?

                          1 Reply Last reply Reply Quote 0
                          • C
                            Cino
                            last edited by

                            the alert at 14:24.

                            
                            2 	2 	UDP 	ET SCAN Sipvicious User-Agent Detected (friendly-scanner) 	Attempted Information Leak 	98.172.131.198 	5071 	-> 	x.x.x.x 	5060 	1:2011716:3 	07/11-14:24:32
                            3 	2 	UDP 	ET SCAN Sipvicious User-Agent Detected (friendly-scanner) 	Attempted Information Leak 	98.172.131.198 	5067 	-> 	x.x.x.x 	5060 	1:2011716:3 	07/11-09:07:36
                            
                            

                            going to update to 2.4.1 shortly.. but this kind of issue I would think is because of the binary

                            1 Reply Last reply Reply Quote 0
                            • E
                              eri--
                              last edited by

                              Is this afetr a snort soft restart(with HUP signal)?

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.