• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Faq into Snort modes

Scheduled Pinned Locked Moved pfSense Packages
6 Posts 3 Posters 11.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    Snailer
    last edited by May 31, 2007, 12:15 PM

    I like to know more about the concepts or differences about the various Snort modes; ie lowmem and ac-sparsebands. *
    And how it affects Snort. Who can give me some pointers please about this topic.
    2nd: Is it a good idea that a faq or sticky-topic about this topic in relation with pfsense is being added to the documentation forum section?

    • I have just upgraded pfsense's system ram to 512mb. (max'd out).
    1 Reply Last reply Reply Quote 0
    • B
      bellera
      last edited by Jun 1, 2007, 8:01 AM Jun 1, 2007, 8:00 AM

      Hello!

      snort is a very complex tool. You should go to its official manual:

      http://www.snort.org/docs/snort_htmanuals/htmanual_261/node32.html

      ac Aho-Corasick Full (high memory, best performance)
      ac-std Aho-Corasick Standard (moderate memory, high performance)
      ac-bnfa Aho-Corasick NFA (low memory, high performance)
      acs Aho-Corasick Sparse (small memory, moderate performance)
      ac-banded Aho-Corasick Banded (small memory, moderate performance)
      ac-sparsebands Aho-Corasick Sparse-Banded (small memory, high performance)
      lowmem Low Memory Keyword Trie (small memory, low performance)

      Some rules can cause snort not to start if you are using lowmem. I'm running standard+community+bleeding+local rules on a snort box (external to pfSense) and I have:

      config detection: search-method ac-bnfa

      pfSense snort configurator uses only standard+local rules and I think it works with lowmem algorim.

      Regards,

      Josep Pujadas

      1 Reply Last reply Reply Quote 0
      • T
        teck9
        last edited by Jun 3, 2007, 4:45 AM

        i dont see ac-bnfa in pfsense ???

        1 Reply Last reply Reply Quote 0
        • B
          bellera
          last edited by Jun 3, 2007, 5:42 PM Jun 3, 2007, 5:40 PM

          Hello!

          If you want to modify some configuration parameters for your pfSense and the possible values are not listed in the web configurator, you can follow these steps (at your own risk):

          1. Go to [Diagnostics][Backup/Restore] and download the ALL configuration to your PC. Be careful! The XML file has sensible information about your LANs & WANs. Save it in a VERY secure folder!

          2. Copy your XML file with another name and edit it.

          3. For snort performance search the <snort>tag. Some lines after you have:

          <performance>lowmem</performance>

          4. Change lowmem for your desired value.

          5. Save changes.

          6. Go a new time to [Diagnostics][Backup/Restore] and make ALL restore. Of course, this operation will reboot your firewall !!!

          After rebooting, if you want to see if snort is running go to the SSH shell and type:

          ps -aux | grep snort

          You should see snort process running …

          I don't know why the GUI has'nt more options for snort performance. Perhaps is for reduce CPU charge. Be careful with the changes ...

          Note: If you edit a new time with GUI your snort settings you will lose your changes made by this method.

          Other possible changes using the XML "method":

          http://faq.pfsense.com/index.php?action=artikel&cat=10&id=38&artlang=en&highlight=hidden

          Regards,

          Josep Pujadas</snort>

          1 Reply Last reply Reply Quote 0
          • T
            teck9
            last edited by Jun 7, 2007, 9:37 AM

            it worked thanks!!

            1 Reply Last reply Reply Quote 0
            • B
              bellera
              last edited by Jun 7, 2007, 1:02 PM

              Ok!

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received