• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Snort: Two firewalls, missing a lot of rules although similar configuration/setup (Solved)

Scheduled Pinned Locked Moved IDS/IPS
5 Posts 2 Posters 584 Views 2 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T Offline
    tsmalmbe
    last edited by tsmalmbe Dec 21, 2018, 4:54 PM Dec 20, 2018, 10:03 PM

    My interface settings and global settings are identical on firewall A & B. The rules available are different. Firewall A seems to be missing a big amount of rules/categories. Can anyone help with this?

    This is FIREWALL A
    0_1545343177732_ruleset_a.PNG

    This is firewall B
    0_1545343334256_ruleset_b-1.PNG

    0_1545343359044_ruleset_b-2.PNG

    Security Consultant at Mint Security Ltd - www.mintsecurity.fi

    1 Reply Last reply Reply Quote 0
    • B Offline
      bmeeks
      last edited by Dec 21, 2018, 2:09 PM

      The extraction of the Snort Subscriber Rules did not fully complete on firewall A. One possible reason is firewall A ran out of disk space in the /tmp directory. That's where the rules archives are downloaded to and extracted for copying to the system volume.

      Do a Forced Update of the rules on firewall A and see if that resolves the problem. Also make sure firewall A has at least 250 MB of free space in /tmp before you do the forced update.

      1 Reply Last reply Reply Quote 1
      • T Offline
        tsmalmbe
        last edited by Dec 21, 2018, 3:38 PM

        Good call and will test that. A is actually using a ramdisk of 120M and the other one is using no ramdisk at all. This was a difference I hadn't seen. No actual recollection of what and why this configuraiton is like that.

        Security Consultant at Mint Security Ltd - www.mintsecurity.fi

        1 Reply Last reply Reply Quote 0
        • T Offline
          tsmalmbe
          last edited by Dec 21, 2018, 4:53 PM

          This was it. What a simple solution for once.

          Security Consultant at Mint Security Ltd - www.mintsecurity.fi

          B 1 Reply Last reply Dec 21, 2018, 8:25 PM Reply Quote 0
          • B Offline
            bmeeks @tsmalmbe
            last edited by Dec 21, 2018, 8:25 PM

            @tsmalmbe said in Snort: Two firewalls, missing a lot of rules although similar configuration/setup (Solved):

            This was it. What a simple solution for once.

            Glad you got it sorted out. Snort or Suricata and RAM disks are not good matches. I always recommend no RAM disk when running either of those two packages.

            1 Reply Last reply Reply Quote 0
            4 out of 5
            • First post
              4/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received