Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort: Two firewalls, missing a lot of rules although similar configuration/setup (Solved)

    Scheduled Pinned Locked Moved IDS/IPS
    5 Posts 2 Posters 506 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tsmalmbe
      last edited by tsmalmbe

      My interface settings and global settings are identical on firewall A & B. The rules available are different. Firewall A seems to be missing a big amount of rules/categories. Can anyone help with this?

      This is FIREWALL A
      0_1545343177732_ruleset_a.PNG

      This is firewall B
      0_1545343334256_ruleset_b-1.PNG

      0_1545343359044_ruleset_b-2.PNG

      Security Consultant at Mint Security Ltd - www.mintsecurity.fi

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        The extraction of the Snort Subscriber Rules did not fully complete on firewall A. One possible reason is firewall A ran out of disk space in the /tmp directory. That's where the rules archives are downloaded to and extracted for copying to the system volume.

        Do a Forced Update of the rules on firewall A and see if that resolves the problem. Also make sure firewall A has at least 250 MB of free space in /tmp before you do the forced update.

        1 Reply Last reply Reply Quote 1
        • T
          tsmalmbe
          last edited by

          Good call and will test that. A is actually using a ramdisk of 120M and the other one is using no ramdisk at all. This was a difference I hadn't seen. No actual recollection of what and why this configuraiton is like that.

          Security Consultant at Mint Security Ltd - www.mintsecurity.fi

          1 Reply Last reply Reply Quote 0
          • T
            tsmalmbe
            last edited by

            This was it. What a simple solution for once.

            Security Consultant at Mint Security Ltd - www.mintsecurity.fi

            bmeeksB 1 Reply Last reply Reply Quote 0
            • bmeeksB
              bmeeks @tsmalmbe
              last edited by

              @tsmalmbe said in Snort: Two firewalls, missing a lot of rules although similar configuration/setup (Solved):

              This was it. What a simple solution for once.

              Glad you got it sorted out. Snort or Suricata and RAM disks are not good matches. I always recommend no RAM disk when running either of those two packages.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.