Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort not starting on pfsense 2.4.4 release p1

    Scheduled Pinned Locked Moved IDS/IPS
    5 Posts 3 Posters 758 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      smrehan00
      last edited by

      Hello everyone! I am having trouble getting snort to work. I was able to install the package without any problems at all. I followed the following tutorial to configure snort:
      https://www.youtube.com/watch?v=-GgqYq5-EBg

      I have replicated the entire process and when I go to start the service it spins for a couple of seconds and then nothing.

      I am attaching screenshots of the logs that I was able to collect. It shows the services started but there is an error which I am unable to understand. Anyone in the community care to shed some light ? Below are the screenshots. Thank you in advance.

      0_1552070616295_1.JPG

      0_1552070628423_2.jpg

      0_1552070641872_3.JPG

      0_1552070652107_4.JPG

      0_1552070662571_5.JPG

      0_1552070670986_6.JPG

      0_1552070678022_7.png

      0_1552070687325_8.png

      0_1552070694938_9.png

      0_1552070706785_10.png

      0_1552070715251_11.png

      0_1552070725254_12.png

      0_1552070734664_13.png

      0_1552070746913_14.png

      0_1552070759968_15.png

      0_1552070770215_16.png

      0_1552070826431_starting snort.JPG

      0_1552070869136_services.JPG

      0_1552070994718_snort logs scr.JPG

      0_1552071021244_snort logs 2.JPG

      0_1552071035119_snort scr 3.JPG

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN Offline
        NogBadTheBad
        last edited by NogBadTheBad

        In EXTERNAL_NET you have !any defined, not sure how you've done it.

        0_1552071600665_1552070977387-snort-logs-scr.jpg

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        S 1 Reply Last reply Reply Quote 0
        • bmeeksB Offline
          bmeeks
          last edited by

          @NogBadTheBad is correct. Somehow you have managed to get !any defined in the EXTERNAL_NET variable. I am not sure how that happened. The default value for EXTERNAL_NET is !HOME_NET.

          When you go to the INTERFACE SETTINGS tab for your WAN interface and click the View List button beside the EXTERNAL_NET drop-down selector, what do you see in the dialog that pops up?

          1 Reply Last reply Reply Quote 0
          • S Offline
            smrehan00 @NogBadTheBad
            last edited by

            @nogbadthebad
            I saw this error message in the logs and was unsure how it happened. I didn't modify any rules. I just downloaded them as directed in the tutorials. I am working with free rules only. No paid subscription for snort rules. Any workaround for this? Kindly let me know.

            1 Reply Last reply Reply Quote 0
            • NogBadTheBadN Offline
              NogBadTheBad
              last edited by NogBadTheBad

              If you can't figure out how !any got there, i'd be tempted to remove snort after unticking Keep Snort Settings After Deinstal then do a re install.

              I'd follow these steps to configure snort as written by @bmeeks who maintains the snort package.

              https://forum.netgate.com/topic/55095/quick-snort-setup-instructions-for-new-users/147

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.