• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Snort - How to block specific file types

Scheduled Pinned Locked Moved IDS/IPS
4 Posts 3 Posters 2.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    corpengineer
    last edited by Jul 6, 2016, 10:40 PM

    Hello there:

    Running pfSense version 2.3.1-p5

    We have a very basic Snort setup.  When I go to configure custom rules, and something like:

    alert tcp any any -> any any (msg:"whatever"; file_type:MSEXEC;)

    The Gui comes back with an error:

    Custom rules have errors: Fatal Error, Quitting..ERROR: /usr/local/etc/snort/snort_45587_em1/rules/custom.rules(1) 'MSEXEC' is not a configured file type.Initializing rule chains…

    For any file type I enter, it yields the same error message.

    Any help would be much appreciated.

    Thank you.

    1 Reply Last reply Reply Quote 0
    • B
      bmeeks
      last edited by Jul 6, 2016, 11:39 PM

      The file inspect option is not currently enabled in the pfSense build of Snort.  This is because when it was first available there were some runtime errors I experienced on FreeBSD (at least within pfSense).  As the option was still a bit experiemental at the time, I did not pursue tracking down the problems.  That option is still disabled on pfSense.  I can look into turning it on in a future package update on pfSense.

      Bill

      1 Reply Last reply Reply Quote 0
      • A
        AR15USR
        last edited by Jul 6, 2016, 11:47 PM

        @bmeeks:

        …I can look into turning it on in a future package update on pfSense.

        Bill

        +1 That would be great.


        2.6.0-RELEASE

        1 Reply Last reply Reply Quote 0
        • C
          corpengineer
          last edited by Jul 7, 2016, 7:30 PM

          Thank you.  If possible, that would be great to add in the next update.

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received