Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Latest Snort Upgrade error in library engine

    Scheduled Pinned Locked Moved IDS/IPS
    30 Posts 12 Posters 10.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • morrealeM
      morreale
      last edited by

      not running the nanobsd version.

      i will remove all remnants and try again.

      thanks for the help

      Release: pfSense 2.3.4 p1(amd64)
      M/B: Supermicro A1SRi-2758F-O
      SSD: 128GB
      RAM: 2x8Gb Kingston 1600MHz DDR3L PC3-12800 ECC
      AP: Cisco

      1 Reply Last reply Reply Quote 0
      • morrealeM
        morreale
        last edited by

        @bmeeks:

        Or for an even more radical approach, remove the Snort package again, open a shell command line session and delete all the snort directories you see in /usr/local/lib, then reinstall Snort.

        Bill

        did this.  i like clean :)

        now working again.  thanks Bill

        Release: pfSense 2.3.4 p1(amd64)
        M/B: Supermicro A1SRi-2758F-O
        SSD: 128GB
        RAM: 2x8Gb Kingston 1600MHz DDR3L PC3-12800 ECC
        AP: Cisco

        1 Reply Last reply Reply Quote 0
        • bmeeksB
          bmeeks
          last edited by

          @morreale:

          @bmeeks:

          Or for an even more radical approach, remove the Snort package again, open a shell command line session and delete all the snort directories you see in /usr/local/lib, then reinstall Snort.

          Bill

          did this.  i like clean :)

          now working again.  thanks Bill

          Great!  Thanks for the feedback.  Not sure why those directories did not get cleaned on the remove and reinstall, though.  That is supposed to happen.

          Bill

          1 Reply Last reply Reply Quote 0
          • F
            freebs
            last edited by

            Thanks to this thread I was able to get snort working again, but I stall can't get VRT rules or community rules to update at all or even openAppID rules for that matter only ET rules.

            here is a pastebin of the log..  http://pastebin.com/uG6akM28

            Disable SSL Peer is checked… i've also regenerated a new Oinkmaster Code with no good results.

            snort ver. 3.2.9.1_14  snort -2.9.8.3 and barnyard2-1.13 installed

            Any help appreciated!

            1 Reply Last reply Reply Quote 0
            • F
              freebs
              last edited by

              omg.. never mind.. it was the dnsbl in pfBlocker that was causing my issue…  now i feel stupid.. pffft!

              1 Reply Last reply Reply Quote 0
              • K
                kidalabama
                last edited by

                Aug 9 20:37:15 php-fpm 23902 /snort/snort_interfaces.php: The command '/usr/local/bin/snort -R 11181 -D -l /var/log/snort/snort_em011181 –pid-path /var/run --nolock-pidfile -G 11181 -c /usr/local/etc/snort/snort_11181_em0/snort.conf -i em0' returned exit code '1', the output was ''
                Aug 9 20:37:15 snort 26537 FATAL ERROR: The dynamic detection library "/usr/local/lib/snort_dynamicrules/server-webapp.so" version 1.0 compiled with dynamic engine library version 2.4 isn't compatible with the current dynamic engine library "/usr/local/lib/snort_dynamicengine/libsf_engine.so" version 2.6.

                2.3.2-RELEASE (amd64)
                built on Tue Jul 19 12:44:43 CDT 2016
                FreeBSD 10.3-RELEASE-p5

                1 Reply Last reply Reply Quote 0
                • K
                  kidalabama
                  last edited by

                  i have solved problem.

                  remove interface and add wan interface after.

                  1 Reply Last reply Reply Quote 0
                  • H
                    humps
                    last edited by

                    @bmeeks:

                    Try completely removing the Snort package and then install it again.  If you have "save settings" checked on the GLOBAL SETTINGS tab, you won't lose any configuration.

                    Bill

                    Just upgraded to PfSense 2.3.2 with snort-2.9.8.3 and experienced this issue… worked like a charm thanks much.

                    1 Reply Last reply Reply Quote 0
                    • M
                      mukpfsense
                      last edited by

                      I am still having this issue. I have tried ALL tips from the Interwebs. No luck.
                      Any more tips?

                      D 1 Reply Last reply Reply Quote 0
                      • D
                        DmitryS @mukpfsense
                        last edited by

                        It helped me:

                        ln -s /usr/lib64/libdnet.so.1.0.1 /usr/lib64/libdnet.1

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.