Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort won't download ruleset

    pfSense Packages
    6
    11
    2.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      j3ffr3y
      last edited by

      Hi all,

      I've had Snort installed for a while now.  But, I had never configured it.  A couple of days ago, I updated to the latest 2.9.2.3.  I'm running on 64 bit 2.0.1 pfSense.  I added in my Oinkmaster code.  But, when I try to update the rules, it runs very quickly and says that it finished.  However, the "Installed Signature Ruleset" shows N/A.  Is this normal?  I've tried rebooting, removing, and re-installing the package with the same results.

      Thanks,

      Jeff

      1 Reply Last reply Reply Quote 0
      • C
        chowtamah
        last edited by

        For testing if you have not selected 'Select Install Emergingthreats rules', select it in Global Settings.
        Click Save.
        Then try again Update rules.

        2.0.2-RELEASE (amd64)  &  2.2.2-RELEASE (amd64)

        Always trying to learn!!

        1 Reply Last reply Reply Quote 0
        • E
          eri--
          last edited by

          Just reinstall the package and should be fine.

          1 Reply Last reply Reply Quote 0
          • J
            j3ffr3y
            last edited by

            "I've tried rebooting, removing, and re-installing the package with the same results."

            After selecting the Emergingthreats rules, it successfully downloads those rules.  Now on the Update Tab, it shows:

            SNORT.ORG >>> N/A
            EMERGINGTHREATS.NET >>> 108bf1fd5ba0ec4d8d304232053459cd

            1 Reply Last reply Reply Quote 0
            • E
              eri--
              last edited by

              You should have the issue in the system log.

              1 Reply Last reply Reply Quote 0
              • J
                j3ffr3y
                last edited by

                What should I expect to see in the system logs?

                Here's the last few days:

                Jul 12 12:03:03 php: : Emergingthreats rules file update downloaded succsesfully
                Jul 12 12:03:03 php: : Snort has restarted with your new set of rules…
                Jul 13 00:03:02 php: : Emergingthreats rules file update downloaded succsesfully
                Jul 13 00:03:02 php: : Snort has restarted with your new set of rules...
                Jul 14 00:03:03 php: : Emergingthreats rules file update downloaded succsesfully
                Jul 14 00:03:03 php: : Snort has restarted with your new set of rules...
                Jul 15 20:31:04 php: /index.php: Successful webConfigurator login for user 'admin' from 192.168.56.6
                Jul 15 20:31:04 php: /index.php: Successful webConfigurator login for user 'admin' from 192.168.56.6

                I just did a manual update and it doesn't show anything in the logs...

                1 Reply Last reply Reply Quote 0
                • J
                  j3ffr3y
                  last edited by

                  Update:

                  I just removed the package and installed the latest version.  Now I'm getting this message every time I try to manually update:

                  "php: /snort/snort_download_rules.php: Please wait… You may only check for New Rules every 15 minutes..."

                  Yes, I've waited the 15 minutes in between tries.

                  1 Reply Last reply Reply Quote 0
                  • C
                    Cino
                    last edited by

                    try this:
                    http://forum.pfsense.org/index.php/topic,51472.msg275191.html#msg275191

                    1 Reply Last reply Reply Quote 0
                    • M
                      mschiek01
                      last edited by

                      @j3ffr3y:

                      Update:

                      I just removed the package and installed the latest version.  Now I'm getting this message every time I try to manually update:

                      "php: /snort/snort_download_rules.php: Please wait… You may only check for New Rules every 15 minutes..."

                      Yes, I've waited the 15 minutes in between tries.

                      I had this exact problem at one point somehow my oink code was bad. I had the premium service and it had expired. I just re-registered the service at snort.org and everything worked fine after that.

                      1 Reply Last reply Reply Quote 0
                      • _
                        _igor_
                        last edited by

                        i had the same problem, but entering my snort-code newly fixed it.

                        1 Reply Last reply Reply Quote 0
                        • J
                          j3ffr3y
                          last edited by

                          I followed Cino's link to completely remove Snort and re-installed.  = Same Issue

                          Tried creating new Snort account and generated a new oinkcode = Same Issue.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.