Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    (Solved) Snort 4.1.6_28 fatal error

    Scheduled Pinned Locked Moved IDS/IPS
    8 Posts 6 Posters 3.6k Views 7 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • fireodoF Offline
      fireodo
      last edited by fireodo

      Hi,

      since this morning I get an error and snort on the LAN interface stops working.
      (I didnt change anything in Snort since months ...)

      FATAL ERROR: /usr/local/etc/snort/snort_10499_igb0/rules/snort.rules(1586) Negated IP ranges that are more general than non-negated ranges are not allowed. Consider inverting the logic: [$EXTERNAL_NET,$HTTP_SERVERS].
      

      Could that be (there was a Rules update) that in the rules is a faulty entry that causes that?

      Edit (if someone stumble over this post) I found the culprit: in the ET Open Rules the "emerging-exploit.rules" has a faulty entry that causes Snort to stop on that interface and exiting with that "FATAL ERROR".

      Thanks and regards,
      fireodo

      Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
      SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
      pfsense 2.8.1 CE
      Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

      E X 2 Replies Last reply Reply Quote 1
      • E Offline
        ESPNSTI @fireodo
        last edited by

        Specifically, it appears to be this rule:

        2054074 - ET EXPLOIT Kingdee Cloud Star Deserialization Vulnerability

        fireodoF 1 Reply Last reply Reply Quote 2
        • fireodoF Offline
          fireodo @ESPNSTI
          last edited by fireodo

          @ESPNSTI said in Snort 4.1.6_28 fatal error:

          Specifically, it appears to be this rule:

          2054074 - ET EXPLOIT Kingdee Cloud Star Deserialization Vulnerability

          Yeah - i guess it should be "[$HOME_NET,$HTTP_SERVERS]" instead of "[$EXTERNAL_NET,$HTTP_SERVERS]" - thanks for researching!

          Its sad that 1 faulty rule can render useless a whole important category ... 🙁

          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
          pfsense 2.8.1 CE
          Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

          1 Reply Last reply Reply Quote 1
          • X Offline
            Xquizet @fireodo
            last edited by

            @fireodo
            The culprit: in the ET Open Rules the "emerging-exploit.rules" has a faulty entry that causes Snort to stop on that interface and exiting with that "FATAL ERROR".

            This is what was causing the error for me as well, and unchecking the box for this allowed Snort to activate and start working again.

            1 Reply Last reply Reply Quote 0
            • JonathanLeeJ Offline
              JonathanLee
              last edited by JonathanLee

              https://forum.netgate.com/topic/200784/resolved-snort-and-suricata-service-startup-failures-on-et-rules-update There are two rules with issues

              SID 2054074 Fix: Manually corrected the broken variable logic by changing the conflicting $EXTERNAL_NET reference to $HOME_NET, allowing the engine to mathematically resolve the network paths cleanly.

              SID 2033776 Fix: Cleaned up the broken trailing regular expression string parameters to satisfy the Snort parser.Toggled the interface back on to complete the reload cycle.

              or just disable those two rules and it will start

              Make sure to upvote

              1 Reply Last reply Reply Quote 0
              • R Offline
                RKiFkRyCevGvpLeXMove
                last edited by

                Here was my fix based on your info:

                Services -> Snort
                SID Mgmt -> Enable Automatic SID State Management -> Enable
                Save
                Add
                List Name: fix_extnet
                2054074 "EXTERNAL_NET" "HOME_NET"
                Save
                SID Management List Interface Assignments -> Modify SID List -> fix_extnet
                Save

                Then I tried starting snort from the pfsense dashboard, and it did not start. So I went back to Services -> Snort, Snort Interfaces -> Snort Status -> Start

                Now it's back up and running.

                Thanks for your help in finding the problem.

                D 1 Reply Last reply Reply Quote 2
                • D Offline
                  DBMandrake @RKiFkRyCevGvpLeXMove
                  last edited by

                  @RKiFkRyCevGvpLeXMove
                  Thank you for this - worked perfectly!

                  1 Reply Last reply Reply Quote 0
                  • fireodoF fireodo referenced this topic on
                  • fireodoF Offline
                    fireodo
                    last edited by

                    10.06.2026 Faulty rule was corrected by Emerging Threat maintainer!

                    Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                    SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                    pfsense 2.8.1 CE
                    Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.