Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort: Won't Update, bad checksum

    IDS/IPS
    10
    22
    12.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pfSenseSnort
      last edited by

      @bmeeks and Paint,

      Thank you for the info.

      It's working now.

      Snort is the only package I use in pfSense and I use on both interfaces ( strict mode).

      It's perfect.. I love it.

      1 Reply Last reply Reply Quote 0
      • U
        user12
        last edited by

        Same here, working now!

        1 Reply Last reply Reply Quote 0
        • D
          DeeeePIMPact
          last edited by

          Worked on 7/12/16 BUT hasn't updated since.  I "Forced Update" and I get a

          "Snort GPLv2 Community Rules md5 download failed.
          Server returned error code 0."

          Any suggestions?

          1 Reply Last reply Reply Quote 0
          • P
            Paint
            last edited by

            @DeeeePIMPact:

            Worked on 7/12/16 BUT hasn't updated since.  I "Forced Update" and I get a

            "Snort GPLv2 Community Rules md5 download failed.
            Server returned error code 0."

            Any suggestions?

            Try this…. https://forum.pfsense.org/index.php?topic=114960.msg638743#msg638743

            pfSense i5-4590
            940/880 mbit Fiber Internet from FiOS
            BROCADE ICX6450 48Port L3-Managed Switch w/4x 10GB ports
            Netgear R8000 AP (DD-WRT)

            1 Reply Last reply Reply Quote 0
            • D
              DeeeePIMPact
              last edited by

              Thank You for the quick response!  I got it working.  In the last 2 days I've installed squid.

              I reverted back to a early restore point when I didn't install squid in the last 2 days and snort updates correctly.

              I am guessing squid is somehow blocking snort updates, and pfsense packages.

              1 Reply Last reply Reply Quote 0
              • D
                DeeeePIMPact
                last edited by

                I figured I'd update this with what turned out to be the actual problem.

                It was not SQUID it was PFBLOCKER and a BOGON list I had installed from iBlocklist.com….

                PFBLOCKER Bogon list was blocking the SNORT VRT Rules and other updates.  Kind of weird as this hasn't happened before and I've been using these lists for quite sometime...

                ohh well...  at least I figured it out :)

                1 Reply Last reply Reply Quote 0
                • B
                  battles
                  last edited by

                  Has this snort download issue been fixed?  I was planning on buying into the snort rules tomorrow.

                  pfSense 2.3.4-RELEASE-p1 (i386)
                  FreeBSD 10.3-RELEASE-p19
                  pfBlockerNG 2.1.2_1
                  Snort Security 3.2.9.5_3
                  Intel(R) Atom(TM) CPU N270 @ 1.60GHz

                  1 Reply Last reply Reply Quote 0
                  • bmeeksB
                    bmeeks
                    last edited by

                    @battles:

                    Has this snort download issue been fixed?  I was planning on buying into the snort rules tomorrow.

                    Yes, it has been fixed since the day it was reported.  The problem was a corrupted MD5 checksum file stored on the Snort VRT rules web site.

                    Bill

                    1 Reply Last reply Reply Quote 0
                    • K
                      ketaj271969
                      last edited by

                      Hello,

                      I'm also struggling to get rules updated after REinstalling pfSense-pkg-snort-3.2.9.1_14.  I've tried adding and removing line 459 and "force update" per the solution given by Paint on 07/12/2016 with no success. I'm noticing the MD5 codes listed for both the downloaded and expected rules files.

                      Any suggestions about other things I can try?

                      Thanks!

                      Starting rules update…  Time: 2017-01-04 15:45:04
                      Downloading Snort VRT rules md5 file snortrules-snapshot-2983.tar.gz.md5...
                      Checking Snort VRT rules md5 file...
                      There is a new set of Snort VRT rules posted.
                      Downloading file 'snortrules-snapshot-2983.tar.gz'...
                      Done downloading rules file.
                      Snort VRT rules file download failed.  Bad MD5 checksum.
                      Downloaded Snort VRT rules file MD5: 6526bfd0ecb40f147434e9ebf4e6d760
                      Expected Snort VRT rules file MD5: 34582aa575ae67f5618145371cef49bf
                      Snort VRT rules file download failed.  Snort VRT rules will not be updated.
                      Downloading Snort GPLv2 Community Rules md5 file community-rules.tar.gz.md5...
                      Checking Snort GPLv2 Community Rules md5 file...
                      There is a new set of Snort GPLv2 Community Rules posted.
                      Downloading file 'community-rules.tar.gz'...
                      Done downloading rules file.
                      Snort GPLv2 Community Rules file download failed.  Bad MD5 checksum.
                      Downloaded Snort GPLv2 Community Rules file MD5: d41d8cd98f00b204e9800998ecf8427e
                      Expected Snort GPLv2 Community Rules file MD5: 32d134e922390691c91a9a1ad8984d24
                      Snort GPLv2 Community Rules file download failed.  Snort GPLv2 Community Rules will not be updated.
                      Downloading Emerging Threats Open rules md5 file emerging.rules.tar.gz.md5...
                      Checking Emerging Threats Open rules md5 file...
                      There is a new set of Emerging Threats Open rules posted.
                      Downloading file 'emerging.rules.tar.gz'...
                      Done downloading rules file.
                      Emerging Threats Open rules file download failed.  Bad MD5 checksum.
                      Downloaded Emerging Threats Open rules file MD5: d41d8cd98f00b204e9800998ecf8427e
                      Expected Emerging Threats Open rules file MD5: 4530f7b252c063c3521d06f9e2443574
                      Emerging Threats Open rules file download failed.  Emerging Threats Open rules will not be updated.
                      The Rules update has finished.  Time: 2017-01-04 15:48:34

                      1 Reply Last reply Reply Quote 0
                      • P
                        Paint
                        last edited by

                        @ketaj271969:

                        Hello,

                        I'm also struggling to get rules updated after REinstalling pfSense-pkg-snort-3.2.9.1_14.  I've tried adding and removing line 459 and "force update" per the solution given by Paint on 07/12/2016 with no success. I'm noticing the MD5 codes listed for both the downloaded and expected rules files.

                        Any suggestions about other things I can try?

                        Thanks!

                        Starting rules update…  Time: 2017-01-04 15:45:04
                        Downloading Snort VRT rules md5 file snortrules-snapshot-2983.tar.gz.md5...
                        Checking Snort VRT rules md5 file...
                        There is a new set of Snort VRT rules posted.
                        Downloading file 'snortrules-snapshot-2983.tar.gz'...
                        Done downloading rules file.
                        Snort VRT rules file download failed.  Bad MD5 checksum.
                        Downloaded Snort VRT rules file MD5: 6526bfd0ecb40f147434e9ebf4e6d760
                        Expected Snort VRT rules file MD5: 34582aa575ae67f5618145371cef49bf
                        Snort VRT rules file download failed.  Snort VRT rules will not be updated.
                        Downloading Snort GPLv2 Community Rules md5 file community-rules.tar.gz.md5...
                        Checking Snort GPLv2 Community Rules md5 file...
                        There is a new set of Snort GPLv2 Community Rules posted.
                        Downloading file 'community-rules.tar.gz'...
                        Done downloading rules file.
                        Snort GPLv2 Community Rules file download failed.  Bad MD5 checksum.
                        Downloaded Snort GPLv2 Community Rules file MD5: d41d8cd98f00b204e9800998ecf8427e
                        Expected Snort GPLv2 Community Rules file MD5: 32d134e922390691c91a9a1ad8984d24
                        Snort GPLv2 Community Rules file download failed.  Snort GPLv2 Community Rules will not be updated.
                        Downloading Emerging Threats Open rules md5 file emerging.rules.tar.gz.md5...
                        Checking Emerging Threats Open rules md5 file...
                        There is a new set of Emerging Threats Open rules posted.
                        Downloading file 'emerging.rules.tar.gz'...
                        Done downloading rules file.
                        Emerging Threats Open rules file download failed.  Bad MD5 checksum.
                        Downloaded Emerging Threats Open rules file MD5: d41d8cd98f00b204e9800998ecf8427e
                        Expected Emerging Threats Open rules file MD5: 4530f7b252c063c3521d06f9e2443574
                        Emerging Threats Open rules file download failed.  Emerging Threats Open rules will not be updated.
                        The Rules update has finished.  Time: 2017-01-04 15:48:34

                        this looks to be an error on the snort side of things - the md5 for the packages (from Snort) don't match the md5 listed for the download. This happens from time to time and will get resolved at Snort's convenience.

                        pfSense i5-4590
                        940/880 mbit Fiber Internet from FiOS
                        BROCADE ICX6450 48Port L3-Managed Switch w/4x 10GB ports
                        Netgear R8000 AP (DD-WRT)

                        1 Reply Last reply Reply Quote 0
                        • K
                          ketaj271969
                          last edited by

                          Hi -

                          I continue to get this "Bad MD5 Checksum" error on a daily basis.  I'm currently updated to the latest version of pfSense Base system - 2.3.2_1.  I believe that I've configured the Snort service properly (oinkmaster code.

                          If you have any suggestions of what else I could look at, please let me know.


                          Starting rules update…  Time: 2017-01-13 12:05:00
                          Downloading Snort VRT rules md5 file snortrules-snapshot-2983.tar.gz.md5...
                          Checking Snort VRT rules md5 file...
                          There is a new set of Snort VRT rules posted.
                          Downloading file 'snortrules-snapshot-2983.tar.gz'...
                          Done downloading rules file.
                          Snort VRT rules file download failed.  Bad MD5 checksum.
                          Downloaded Snort VRT rules file MD5: 2ea2e701ecf386c5ec88d6b7977c98bc
                          Expected Snort VRT rules file MD5: 3ef18f7d2d38d79739072e4ba57cf32b
                          Snort VRT rules file download failed.  Snort VRT rules will not be updated.
                          Downloading Snort GPLv2 Community Rules md5 file community-rules.tar.gz.md5...
                          Checking Snort GPLv2 Community Rules md5 file...
                          There is a new set of Snort GPLv2 Community Rules posted.
                          Downloading file 'community-rules.tar.gz'...
                          Done downloading rules file.
                          Snort GPLv2 Community Rules file download failed.  Bad MD5 checksum.
                          Downloaded Snort GPLv2 Community Rules file MD5: d41d8cd98f00b204e9800998ecf8427e
                          Expected Snort GPLv2 Community Rules file MD5: 5226c89b677da8a7ab63ca6fa01720fe
                          Snort GPLv2 Community Rules file download failed.  Snort GPLv2 Community Rules will not be updated.
                          Downloading Emerging Threats Open rules md5 file emerging.rules.tar.gz.md5...
                          Checking Emerging Threats Open rules md5 file...
                          There is a new set of Emerging Threats Open rules posted.
                          Downloading file 'emerging.rules.tar.gz'...
                          Done downloading rules file.
                          Emerging Threats Open rules file download failed.  Bad MD5 checksum.
                          Downloaded Emerging Threats Open rules file MD5: d41d8cd98f00b204e9800998ecf8427e
                          Expected Emerging Threats Open rules file MD5: 6d1bebb91cbb9323443399b8d12be408
                          Emerging Threats Open rules file download failed.  Emerging Threats Open rules will not be updated.
                          The Rules update has finished.  Time: 2017-01-13 12:09:16

                          1 Reply Last reply Reply Quote 0
                          • D
                            doktornotor Banned
                            last edited by

                            People, which part of "this is NOT a pfSense issue" is difficult to get?

                            1 Reply Last reply Reply Quote 0
                            • K
                              ketaj271969
                              last edited by

                              To be clear, I didn't say this was a pfSense issue. – I've seen the previous responses to my request,

                              What I'm asking is if there's a different avenue of investigation I might be able to pursue to figure out what the problem might be.  Perhaps with snort.org?

                              You may have noticed from my badge that I'm a newbie here.  I was given the impression that this was a helpful forum.  My misunderstanding.

                              1 Reply Last reply Reply Quote 0
                              • D
                                doktornotor Banned
                                last edited by

                                Yeah, to be clear this is absolutely wrong place to post. Noone here maintains the snort.org webservers so noone here can fix broken checksums they keep uploading over and over and over again. If you have a paid subscription, complain to the Snort guys, if you have none, then you get what you paid for and simply wait till someone fixes it.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.