Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    (bug?) Snort Advanced configuration pass through doesn't work

    Scheduled Pinned Locked Moved pfSense Packages
    1 Posts 1 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      ronenb75
      last edited by

      Snort running on 1.2-BETA-1.

      I've put "config disable_decode_alerts" the "Advenced" tab, the text box "Advanced configuration pass through".

      If I'm looking at the /cf/conf/config.xml, I can see the config in there:

                      <snortadvanced><config><bpfbufsize><bpfmaxbufsize><bpfmaxinsns><configpassthru>config disable_decode_alerts</configpassthru></bpfmaxinsns></bpfmaxbufsize></bpfbufsize></config></snortadvanced> 
      
      

      But if I'm looking at /usr/local/etc/snort/snort.conf, I see just that:

      
      # Snort user pass through configuration
      
      #Rulesets, all optional
      
      

      Which means that there is no configuration passing through to the snort.conf file. even after reboot, it's still empty, though it's still in the "Advanced tab and in the config.xml file.

      Any ideas?
      Is this a bug or I'm doing anything wrong?

      Thanx.

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.