Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort-dev ready for testing. Post issues here.

    Scheduled Pinned Locked Moved pfSense Packages
    23 Posts 10 Posters 10.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      digdug3
      last edited by

      @SectorNine50:

      This is really unimportant, but…

      Is there any chance you can make add a /snort/index.php that redirects to the /index.php for pfSense?

      Every time I'm in snort and I want to get back to my dashboard, I click the pfSense logo and get a "404 Not Found" error because the browser wants to stay in the /snort/ directory...

      I guess I could do it myself, but figured it'd be nice to have in the package! :)

      Doesn't this only happen when you have the widescreen package installed?

      1 Reply Last reply Reply Quote 0
      • C Offline
        Cino
        last edited by

        @digdug3:

        @SectorNine50:

        This is really unimportant, but…

        Is there any chance you can make add a /snort/index.php that redirects to the /index.php for pfSense?

        Every time I'm in snort and I want to get back to my dashboard, I click the pfSense logo and get a "404 Not Found" error because the browser wants to stay in the /snort/ directory...

        I guess I could do it myself, but figured it'd be nice to have in the package! :)

        Doesn't this only happen when you have the widescreen package installed?

        I think your right. Works fine on 2.1 right now

        1 Reply Last reply Reply Quote 0
        • S Offline
          SectorNine50
          last edited by

          @digdug3:

          Doesn't this only happen when you have the widescreen package installed?

          Ah okay good to know!  Thanks.

          1 Reply Last reply Reply Quote 0
          • J Offline
            judex
            last edited by

            Snort-dev seems to loose blocked hosts on 2.0.1 amd64.
            My blocking time is set to 3 hours. A host gets blocked correctly when a matching rule fires. Sometimes this host gets out of snort2c table even if there where multiple new alerts from the same host meanwhile. So it also seems that the remaining blocking time does not get updated after a new alert.

            Greets, Judex

            2.1-RELEASE (amd64)
            built on Wed Sep 11 18:17:48 EDT 2013
            FreeBSD 8.3-RELEASE-p11

            1 Reply Last reply Reply Quote 0
            • J Offline
              judex
              last edited by

              It seems that snort-dev shuts down on the first alert after an automatic rule update. I observed that at leats twice.

              Here's the log:

              Jun 29 00:10:07 gatekeeper snort[62591]: FATAL ERROR: s2c_pf_block() => ioctl() DIOCRADDADDRS: Bad file descriptor
              Jun 29 00:10:07 gatekeeper kernel: em1: promiscuous mode disabled

              2.1-RELEASE (amd64)
              built on Wed Sep 11 18:17:48 EDT 2013
              FreeBSD 8.3-RELEASE-p11

              1 Reply Last reply Reply Quote 0
              • C Offline
                Cino
                last edited by

                @judex:

                It seems that snort-dev shuts down on the first alert after an automatic rule update. I observed that at leats twice.

                Here's the log:

                Jun 29 00:10:07 gatekeeper snort[62591]: FATAL ERROR: s2c_pf_block() => ioctl() DIOCRADDADDRS: Bad file descriptor
                Jun 29 00:10:07 gatekeeper kernel: em1: promiscuous mode disabled

                I was testing whitelist changes today and enabled blocking, I'm seeing the same issues.

                Is there an issue with the pf patch that was applied?

                
                Jul 4 08:28:56 	snort[4839]: FATAL ERROR: s2c_pf_block() => ioctl() DIOCRADDADDRS: Inappropriate ioctl for device
                Jul 4 08:28:56 	snort[4839]: FATAL ERROR: s2c_pf_block() => ioctl() DIOCRADDADDRS: Inappropriate ioctl for device
                
                
                1 Reply Last reply Reply Quote 0
                • D Offline
                  dwood
                  last edited by

                  attempted snort-dev install on two amd64 boxes.  Installation does not finish.  It hangs at "loading package information".

                  Cheers,
                  Dennis.

                  1 Reply Last reply Reply Quote 0
                  • J Offline
                    judex
                    last edited by

                    @dwood:

                    attempted snort-dev install on two amd64 boxes.  Installation does not finish.  It hangs at "loading package information".

                    Cheers,
                    Dennis.

                    +1

                    2.1-RELEASE (amd64)
                    built on Wed Sep 11 18:17:48 EDT 2013
                    FreeBSD 8.3-RELEASE-p11

                    1 Reply Last reply Reply Quote 0
                    • marcellocM Offline
                      marcelloc
                      last edited by

                      It seems like php closure code that you used on snort.inc file is compatible only with php5.3(pfsense 2.1)
                      $snort_calc_iface_subnet_list = function($int) use(&$home_net)

                      Starting package snort-dev…
                      Parse error: syntax error, unexpected T_FUNCTION in /usr/local/pkg/snort/snort.inc on line 183

                      Treinamentos de Elite: http://sys-squad.com

                      Help a community developer! ;D

                      1 Reply Last reply Reply Quote 0
                      • rcfaR Offline
                        rcfa
                        last edited by

                        I get this error:

                        Warning: file_get_contents(/var/log/snort/59183_lagg0/alert): failed to open stream: No such file or directory in /usr/local/www/snort/snort_alerts.php on line 396

                        when I go to the Alerts tab (Services : Snort : Snort Alerts)

                        Rules are downloaded successfully, WAN interface is enabled for snort, but it ain't running.

                        Any ideas?

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.