• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[Solved] Snort GPLv2 Community Rules - Unable to download checksum file

Scheduled Pinned Locked Moved IDS/IPS
41 Posts 9 Posters 7.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    bmeeks @ddepaolis
    last edited by bmeeks Feb 25, 2021, 2:20 PM Feb 25, 2021, 2:12 PM

    @ddepaolis said in Snort GPLv2 Community Rules - Unable to download checksum file:

    @bmeeks
    So will it be available an update for Snort to apply through "Package Manager" ?
    Thanks and regards !

    If the new snort3-community-rules file is compatible, then yes, I will update the GUI code to work with it. That will take several days to make the change and have the pfSense developers review and post it to the Package Manager.

    However, if it turns out the new file is really only designed for the Snort3 binary, then "no", there will not be an update to allow its use. Snort on pfSense uses the 2.9.x binary version, not the Snort3 binary.

    I've sent an email to the Talos team asking about compatibility and if the filename change is an oversight or a planned migration.

    1 Reply Last reply Reply Quote 0
    • M
      monotypeTattoo @bmeeks
      last edited by Feb 25, 2021, 2:39 PM

      @bmeeks thank you for the swift update.

      1 Reply Last reply Reply Quote 0
      • B
        bmeeks
        last edited by Feb 25, 2021, 2:57 PM

        I've heard back from the Talos/Snort team. They are investigating. I think this was just a mistake on their part. Hopefully it self-corrects soon.

        I will post further updates as I have them.

        E 1 Reply Last reply Feb 25, 2021, 3:35 PM Reply Quote 0
        • E
          elvisimprsntr @bmeeks
          last edited by Feb 25, 2021, 3:35 PM

          @bmeeks

          I disabled use custom URL and performed a manual update.

          seems to have download and v2 snort rules now.

          1 Reply Last reply Reply Quote 0
          • B
            bmeeks
            last edited by bmeeks Feb 25, 2021, 3:40 PM Feb 25, 2021, 3:39 PM

            It is fixed now. It was a problem on the Snort/Talos side. They have restored the older Community Rules file now.

            I've marked this thread as [Solved].

            1 Reply Last reply Reply Quote 0
            • D
              ddepaolis
              last edited by Feb 25, 2021, 4:14 PM

              I confirm, I finished to update once again all my rules, GPLv2 too, and I completed on both my PFSense platforms. Really thanks so much for this quick support !

              1 Reply Last reply Reply Quote 0
              • C
                crsesilva
                last edited by Mar 26, 2021, 11:31 PM

                Hello,

                Just wondering if anyone else has this problem again?

                "pfSense CE 2.5.0" "Snort Package Version 4.1.3_2"

                snort_update.png

                https://www.snort.org/downloads/community/snort-community-rules.tar.gz.md5 returns 404 (File not found)
                https://www.snort.org/downloads/community/snort3-community-rules.tar.gz.md5 returns 200 and is a thing.

                I'm sorry to post in a resolved topic, but I believe we have the problem again.

                Thanks.

                S 1 Reply Last reply Mar 27, 2021, 10:09 AM Reply Quote 0
                • S
                  slu @crsesilva
                  last edited by Mar 27, 2021, 10:09 AM

                  @crsesilva
                  yes same here:

                  Starting rules update...  Time: 2021-03-27 11:07:31
                          [...]
                  	Downloading Snort GPLv2 Community Rules md5 file community-rules.tar.gz.md5...
                  	Snort GPLv2 Community Rules md5 download failed.
                  	Server returned error code 404.
                  	Server error message was: 404 Not Found
                  	Snort GPLv2 Community Rules will not be updated.
                  

                  pfSense Gold subscription

                  C 1 Reply Last reply Mar 27, 2021, 8:50 PM Reply Quote 0
                  • C
                    crsesilva @slu
                    last edited by Mar 27, 2021, 8:50 PM

                    @slu

                    Today, in a new download attempt, I was successful.

                    snort_update2.png

                    snort_update3.png

                    Looking at the download options page for snort.org in the community, Snort v2.9 appeared again. Yesterday, only Snort v3.0 available.

                    snort_update1.png

                    I want to believe that it is a one-off mistake and not forcing us to go immediately to Snort 3.0.

                    Thanks.
                    Cheers.

                    1 Reply Last reply Reply Quote 0
                    • M
                      monotypeTattoo
                      last edited by Apr 23, 2021, 6:35 AM

                      This seems to be back:

                      Downloading Snort GPLv2 Community Rules md5 file community-rules.tar.gz.md5...
                      	Snort GPLv2 Community Rules md5 download failed.
                      	Server returned error code 404.
                      	Server error message was: 404 Not Found
                      

                      It looks like the Snort v2.9 community rules have been removed again?

                      d6c6e1dc-b86a-42d9-a0f6-fa59488f4fec-image.png

                      M 1 Reply Last reply Jul 21, 2021, 8:01 AM Reply Quote 0
                      • M
                        monotypeTattoo @monotypeTattoo
                        last edited by monotypeTattoo Jul 21, 2021, 8:01 AM Jul 21, 2021, 8:01 AM

                        Once again the Snort v2.9 community rules have been removed:

                        9d43e353-41d9-4aca-924b-842e1ca24534-image.png

                        Excerpt from update log:

                        	Downloading Snort GPLv2 Community Rules md5 file community-rules.tar.gz.md5...
                        	Snort GPLv2 Community Rules md5 download failed.
                        	Server returned error code 404.
                        	Server error message was: 404 Not Found
                        	Snort GPLv2 Community Rules will not be updated.
                        
                        1 Reply Last reply Reply Quote 0
                        • B
                          bmeeks
                          last edited by Jul 21, 2021, 12:58 PM

                          Yes, I noticed this as well during some Suricata testing in a VM. This is a problem the Snort team will have to resolve.

                          Do NOT attempt to use the Snort3 rules with the 2.9.x binary! If you use any Snort3 rules with either Snort or Suricata, you will break your installation to the point the only recovery method is to remove the package and reinstall it.

                          1 Reply Last reply Reply Quote 0
                          • B
                            bmeeks
                            last edited by Jul 21, 2021, 10:17 PM

                            This issue has once again been solved by the Snort Rules Team. The GPLv2 Community Rules for Snort 2.9.x are available.

                            M 1 Reply Last reply Jul 22, 2021, 7:54 AM Reply Quote 0
                            • M
                              monotypeTattoo @bmeeks
                              last edited by Jul 22, 2021, 7:54 AM

                              @bmeeks Thank you.

                              I did send an email enquiry linking to this thread and describing the problem. I received a very brief reply effectively denying the problem.

                              I suspect the process that creates the community-rules.tar.gz file possibly breaks on occasion?

                              B 1 Reply Last reply Jul 22, 2021, 12:53 PM Reply Quote 0
                              • B
                                bmeeks @monotypeTattoo
                                last edited by Jul 22, 2021, 12:53 PM

                                @monotypetattoo said in [Solved] Snort GPLv2 Community Rules - Unable to download checksum file:

                                @bmeeks Thank you.

                                I did send an email enquiry linking to this thread and describing the problem. I received a very brief reply effectively denying the problem.

                                I suspect the process that creates the community-rules.tar.gz file possibly breaks on occasion?

                                From the little bit I understand via previous email conversations with some of the Snort team members, this is an automated process. It sometimes hiccups, and I guess now that Snort3 is their main focus, they don't always notice if the 2.9.x rules packages fail to build and post correctly.

                                1 Reply Last reply Reply Quote 1
                                • fireodoF fireodo referenced this topic on Jul 31, 2023, 7:55 AM
                                • X
                                  xperttech
                                  last edited by Jul 31, 2023, 1:00 PM

                                  Hi all, I'm new to pfSense.
                                  I just installed it over the weekend and have this very issue from the start. My gateway has never seen the GPLv2 Community Rules for Snort 2.0.x. I find that it has happened a few times in years past. Seems to be back.
                                  Do we need to keep reminding someone to fix this automated process?
                                  Thanks!

                                  B 1 Reply Last reply Jul 31, 2023, 2:18 PM Reply Quote 0
                                  • B
                                    bmeeks @xperttech
                                    last edited by bmeeks Aug 1, 2023, 12:51 PM Jul 31, 2023, 2:18 PM

                                    @xperttech said in [Solved] Snort GPLv2 Community Rules - Unable to download checksum file:

                                    Hi all, I'm new to pfSense.
                                    I just installed it over the weekend and have this very issue from the start. My gateway has never seen the GPLv2 Community Rules for Snort 2.0.x. I find that it has happened a few times in years past. Seems to be back.
                                    Do we need to keep reminding someone to fix this automated process?
                                    Thanks!

                                    This would be something you should take up with the Snort team. Perhaps by joining their mailing list here: https://seclists.org/snort/.

                                    You should also be aware that if you have a Snort VRT subscription (or are registered for their free 30-day aged rules), then you do not need to download the GPL v2 Community Rules separately as they are included within the subscriber and registered packages.

                                    Edited: found out only paid subscribers have the GPLv2 Community Rules included within that archive. Registered users (non-paying) get an archive that does not include the GPLv2 Rules.

                                    DefenderLLCD 1 Reply Last reply Aug 1, 2023, 12:09 AM Reply Quote 0
                                    • DefenderLLCD
                                      DefenderLLC @bmeeks
                                      last edited by DefenderLLC Aug 1, 2023, 2:43 AM Aug 1, 2023, 12:09 AM

                                      @bmeeks said in [Solved] Snort GPLv2 Community Rules - Unable to download checksum file:

                                      @xperttech said in [Solved] Snort GPLv2 Community Rules - Unable to download checksum file:

                                      Hi all, I'm new to pfSense.
                                      I just installed it over the weekend and have this very issue from the start. My gateway has never seen the GPLv2 Community Rules for Snort 2.0.x. I find that it has happened a few times in years past. Seems to be back.
                                      Do we need to keep reminding someone to fix this automated process?
                                      Thanks!

                                      This would be something you should take up with the Snort team. Perhaps by joining their mailing list here: https://seclists.org/snort/.

                                      You should also be aware that if you have a Snort VRT subscription (or are registered for their free 30-day aged rules), then you do not need to download the GPL v2 Community Rules separately as they are included within the subscriber and registered packages.

                                      I’m having the same exact issue although I’m a paid subscriber, so I just disabled the community rules. Something definitely happened in the last few days.

                                      Update: It looks like Snort removed the community ruleset for v2.9.. #Shocker

                                      https://www.snort.org/downloads#rules

                                      fireodoF 1 Reply Last reply Aug 1, 2023, 10:31 AM Reply Quote 0
                                      • fireodoF
                                        fireodo @DefenderLLC
                                        last edited by Aug 1, 2023, 10:31 AM

                                        @DefenderLLC said in [Solved] Snort GPLv2 Community Rules - Unable to download checksum file:

                                        Something definitely happened in the last few days.

                                        I guess asking Talos would bring clarity ... ;-)

                                        Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                        SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                        pfsense 2.7.2 CE
                                        Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

                                        S 1 Reply Last reply Aug 1, 2023, 12:59 PM Reply Quote 0
                                        • S
                                          slu @fireodo
                                          last edited by Aug 1, 2023, 12:59 PM

                                          @bmeeks
                                          any change to bring SNORT 3.x to pfSense?
                                          I guess this is much work, otherwise you would have done it a long time ago?

                                          pfSense Gold subscription

                                          B 1 Reply Last reply Aug 1, 2023, 1:04 PM Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received