Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort and Interface Enable/Disable

    Scheduled Pinned Locked Moved pfSense Packages
    60 Posts 8 Posters 20.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • AhnHELA
      AhnHEL
      last edited by

      Ok, so far so good.  No errors, no problems and running smooth.  Looking at the below pic, Snort Rules Tab, Rule Changed By User, very nice.

      Untitled.png
      Untitled.png_thumb

      AhnHEL (Angel)

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        @onhel:

        Ok, so far so good.  No errors, no problems and running smooth.  Looking at the below pic, Snort Rules Tab, Rule Changed By User, very nice.

        Good to hear.  Running well so far for me as well on my test machines.

        I added the special color-coding for the disablesid and enablesid changes made by the user because I thought at some point down the road folks might want to be able to quickly tell which rules they toggled to enabled or disabled from their default state.  There are two small buttons at the top of the page on the right to let you "reset to defaults" the currently selected rule category, or "reset all" to reset all the rules in all categories to defaults.  These two buttons just remove all your enablesid/disablesid changes for either the selected category, or all categories, (depending on which button you click).

        SID enable/disable modifications should now persist across rule updates and Snort instance stops and starts.  Maybe some of the other posters in this thread complaing about this bug will contact me via PM and I can provide them the files to test with so they can test the persistence of enablesid/disablesid changes in this new code.

        1 Reply Last reply Reply Quote 0
        • S
          Supermule Banned
          last edited by

          Will do! Very busy at ATM!

          1 Reply Last reply Reply Quote 0
          • E
            eri--
            last edited by

            Package of snort has been update with changes proposed.
            If you would like to test just reinstall snort.

            1 Reply Last reply Reply Quote 0
            • S
              Supermule Banned
              last edited by

              YOU are the CHAMP Ermal!!

              1 Reply Last reply Reply Quote 0
              • S
                Supermule Banned
                last edited by

                I get this error….

                Snort_error.jpg
                Snort_error.jpg_thumb

                1 Reply Last reply Reply Quote 0
                • S
                  Supermule Banned
                  last edited by

                  More errors….I uninstalled package and reinstalled to see if it fixed the unicode error reported in the previous post.

                  It resulted in this...

                  Stuck on auto-enabling flowbits and error line 375 in /usr/local/pkg/snort/snort_check_for_rule_updates.php on line 375

                  Snort_error_2.jpg
                  Snort_error_2.jpg_thumb

                  1 Reply Last reply Reply Quote 0
                  • AhnHELA
                    AhnHEL
                    last edited by

                    Have you gotten past this error yet, Super?

                    I'm still running Bill's code without any errors and now that the actual Snort package has been updated, I'm reluctant to upgrade if its going to be a showstopper.

                    I think a new thread should be started with the appropriate Testing Snort 2.9.2.3 pkg v. 2.5.3 as a title.

                    AhnHEL (Angel)

                    1 Reply Last reply Reply Quote 0
                    • S
                      Supermule Banned
                      last edited by

                      I deleted the package completely and installed again.

                      The unicode error went away and SSL_State emerged.

                      I checked the SSL_State preprocessor and it runs fine! Without the checkbox checked, it crashes…

                      1 Reply Last reply Reply Quote 0
                      • S
                        Supermule Banned
                        last edited by

                        Updated the package to 2.5.3 via Webgui and gets the unicode map file error again!!!!!!

                        So basically have to do a manual uninstall and install again since it apparently is not able to update the package.

                        Not good…. Something is wrong in the package building section of events.

                        Production remains on 2.5.2 until this is resolved.

                        1 Reply Last reply Reply Quote 0
                        • S
                          Supermule Banned
                          last edited by

                          DONT UPGRADE THE PACKAGE TO 2.5.3!!!!!!!!!!!!!!!!!!!!

                          Even a fresh install triggers the rule_updates.php error!!!

                          So currently running the testbox WITHOUT snort….!

                          fatal_error.jpg
                          fatal_error.jpg_thumb

                          1 Reply Last reply Reply Quote 0
                          • E
                            eri--
                            last edited by

                            Reinstall resolved the issue

                            1 Reply Last reply Reply Quote 0
                            • S
                              Supermule Banned
                              last edited by

                              Have you changed it Ermal???

                              Both reinstall and fresh install is not working!

                              1 Reply Last reply Reply Quote 0
                              • bmeeksB
                                bmeeks
                                last edited by

                                The error in the Updates tab is due to a small change made to preface all the new function names in the code with "snort_".  Ermal patched these up just before release to add the prefix, and it looks like one call in the UPDATES tab code got missed.  It's looking for the old function name of "build_sig_msg_map()" instead of the patched up name of "snort_build_sid_msg_map()".

                                It's an easy fix, and hopefully Ermal can push it out shortly.

                                Bill

                                1 Reply Last reply Reply Quote 0
                                • S
                                  Supermule Banned
                                  last edited by

                                  Thanks Bill!!

                                  1 Reply Last reply Reply Quote 0
                                  • E
                                    eri--
                                    last edited by

                                    Yes i fixed but it takes about 30 minutes for the package code to sync.

                                    1 Reply Last reply Reply Quote 0
                                    • K
                                      KeltecRFB
                                      last edited by

                                      Thanks all for fixing the update error, I will fix it tonight when I get home.

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.