Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Version 2.1.5 Snort Missing from Available Packages

    Scheduled Pinned Locked Moved IDS/IPS
    17 Posts 3 Posters 3.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mschiek01
      last edited by

      On version 2.1.5 I am trying to reinstall snort and it is missing from the available package list as well as the installed list.

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        Yeah, gone forever. Upgrade your pfSense. https://github.com/pfsense/pfsense-packages/pull/1065

        1 Reply Last reply Reply Quote 0
        • M
          mschiek01
          last edited by

          Yeah I would love to upgrade but unfortunately not all the packages will reinstall on 2.2.4 either.  I already tried on a test box.  Mailscanner & Dansguardian just to name a few.  There has got to be a way to reinstall it.

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by

            You did not get the point, I guess? IDS without rules is completely useless.

            1 Reply Last reply Reply Quote 0
            • M
              mschiek01
              last edited by

              Not sure I understand what your are saying why would the rules not be available?

              1 Reply Last reply Reply Quote 0
              • D
                doktornotor Banned
                last edited by

                Perhaps, read the info linked above?

                1 Reply Last reply Reply Quote 0
                • M
                  mschiek01
                  last edited by

                  I read the posting thank you.

                  The rule sets were already there as the installation was pre-existing.  Something was better than nothing.  Removing it from the repository just created more problems than it fixes.  A simple warning would have sufficed.

                  1 Reply Last reply Reply Quote 0
                  • D
                    doktornotor Banned
                    last edited by

                    Dude… what warning? Warning: Your are installing a completely useless package that won't do anything?

                    Noone who installs this will have any rules. And won't be able to download them. There are no "pre-existing" rules. They are removed with the PBI.

                    1 Reply Last reply Reply Quote 0
                    • M
                      mschiek01
                      last edited by

                      Here is a current system running 2.1.5 with snort installed.  Either I am not understanding you or snort is not reporting the rule set properly as this shows it is updating correctly.

                      I am not trying to start an argument I am just trying to understand what is going on.  You should understand that maybe everyone does not have the same expertise as you have that is why this a community.

                      ![2.1.5.snort current.jpg](/public/imported_attachments/1/2.1.5.snort current.jpg)
                      ![2.1.5.snort current.jpg_thumb](/public/imported_attachments/1/2.1.5.snort current.jpg_thumb)

                      1 Reply Last reply Reply Quote 0
                      • D
                        doktornotor Banned
                        last edited by

                        Dude. When you reinstall a package, the PBI dir gets deleted and the rules are gone. This debate is incredibly pointless waste of time.

                        1 Reply Last reply Reply Quote 0
                        • M
                          mschiek01
                          last edited by

                          What debate I was just trying to understand what was going on.  Once again maybe you could understand not everyone is as knowledgeable as you.  Thanks for your time.

                          1 Reply Last reply Reply Quote 0
                          • G
                            G.D. Wusser Esq.
                            last edited by

                            Emerging threat rules still work and download fine.
                            Why kill the whole package just because one of the providers quit offering updates?

                            1 Reply Last reply Reply Quote 0
                            • D
                              doktornotor Banned
                              last edited by

                              Your two viable options:

                              • upgrade pfSense (should have done that long ago anyway)
                              • use Suricata which doesn't hardcode rules versions (the package is no longer updated either, because newer versions don't even compile on FreeBSD 8.x any more).

                              Further rants here will get you exactly nowhere.

                              1 Reply Last reply Reply Quote 0
                              • G
                                G.D. Wusser Esq.
                                last edited by

                                There are other options too, like hosting Snort separately from pfSense, for example.

                                1 Reply Last reply Reply Quote 0
                                • D
                                  doktornotor Banned
                                  last edited by

                                  I don't think you have a clue what you are talking about really…

                                  1 Reply Last reply Reply Quote 0
                                  • G
                                    G.D. Wusser Esq.
                                    last edited by

                                    Snort is not exclusive to pfSense. It can be installed separately.

                                    1 Reply Last reply Reply Quote 0
                                    • D
                                      doktornotor Banned
                                      last edited by

                                      Yes. So install it.

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.