Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort not starting on pfsense 2.4.4 release p1

    Scheduled Pinned Locked Moved IDS/IPS
    5 Posts 3 Posters 744 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      smrehan00
      last edited by

      Hello everyone! I am having trouble getting snort to work. I was able to install the package without any problems at all. I followed the following tutorial to configure snort:
      https://www.youtube.com/watch?v=-GgqYq5-EBg

      I have replicated the entire process and when I go to start the service it spins for a couple of seconds and then nothing.

      I am attaching screenshots of the logs that I was able to collect. It shows the services started but there is an error which I am unable to understand. Anyone in the community care to shed some light ? Below are the screenshots. Thank you in advance.

      0_1552070616295_1.JPG

      0_1552070628423_2.jpg

      0_1552070641872_3.JPG

      0_1552070652107_4.JPG

      0_1552070662571_5.JPG

      0_1552070670986_6.JPG

      0_1552070678022_7.png

      0_1552070687325_8.png

      0_1552070694938_9.png

      0_1552070706785_10.png

      0_1552070715251_11.png

      0_1552070725254_12.png

      0_1552070734664_13.png

      0_1552070746913_14.png

      0_1552070759968_15.png

      0_1552070770215_16.png

      0_1552070826431_starting snort.JPG

      0_1552070869136_services.JPG

      0_1552070994718_snort logs scr.JPG

      0_1552071021244_snort logs 2.JPG

      0_1552071035119_snort scr 3.JPG

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by NogBadTheBad

        In EXTERNAL_NET you have !any defined, not sure how you've done it.

        0_1552071600665_1552070977387-snort-logs-scr.jpg

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        S 1 Reply Last reply Reply Quote 0
        • bmeeksB
          bmeeks
          last edited by

          @NogBadTheBad is correct. Somehow you have managed to get !any defined in the EXTERNAL_NET variable. I am not sure how that happened. The default value for EXTERNAL_NET is !HOME_NET.

          When you go to the INTERFACE SETTINGS tab for your WAN interface and click the View List button beside the EXTERNAL_NET drop-down selector, what do you see in the dialog that pops up?

          1 Reply Last reply Reply Quote 0
          • S
            smrehan00 @NogBadTheBad
            last edited by

            @nogbadthebad
            I saw this error message in the logs and was unsure how it happened. I didn't modify any rules. I just downloaded them as directed in the tutorials. I am working with free rules only. No paid subscription for snort rules. Any workaround for this? Kindly let me know.

            1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad
              last edited by NogBadTheBad

              If you can't figure out how !any got there, i'd be tempted to remove snort after unticking Keep Snort Settings After Deinstal then do a re install.

              I'd follow these steps to configure snort as written by @bmeeks who maintains the snort package.

              https://forum.netgate.com/topic/55095/quick-snort-setup-instructions-for-new-users/147

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.