Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    SNORT service stops

    pfSense Packages
    2
    5
    5390
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      DigitalJer last edited by

      Hi all,

      pfsense 1.2.3-RELEASE
      SNORT 2.8.4.1_5 pkg v.1.7

      SNORT was configured to auto-update rules, and has been OK.  However it seems to just quit; daily.  So I config'd it to update rules daily, as a manual update restarts the service OK - but that didn't seem to help.  The manual updates still work, and it starts OK - but I can't figure out why it stops in the first place.  When running, it works great…blocks offending IP's etc like a champ.

      –------------------------------------------------
      2.4.3-RELEASE (amd64)
      built on Mon Mar 26 18:02:04 CDT 2018
      FreeBSD 11.1-RELEASE-p7
      VM in ESXi 5.5
      1 x 1000baseTX (WAN)
      1 x 1000baseTX (LAN)

      1 Reply Last reply Reply Quote 0
      • J
        jamesdean last edited by

        Wait what ?

        Does snort stop after auto updates or does does snort stop after a few minutes of start ?

        1 Reply Last reply Reply Quote 0
        • D
          DigitalJer last edited by

          @jamesdean:

          Does snort stop after auto updates or does does snort stop after a few minutes of start ?

          It seems to quit after a few hours or more, not sure.  Not sure if it's actually stopping and cant' restart after the auto-updates, that's just a hunch.  I just know that when I check it on a daily basis, it's usually stopped.  I can re-start the service from the webgui OK.  Manually updating the rules also seems to restart the service OK.

          Now that I've done that for today, I know that by tomorrow the SNORT service will be in a Stopped status.

          Sorry if that wasn't clear the first time :(

          –------------------------------------------------
          2.4.3-RELEASE (amd64)
          built on Mon Mar 26 18:02:04 CDT 2018
          FreeBSD 11.1-RELEASE-p7
          VM in ESXi 5.5
          1 x 1000baseTX (WAN)
          1 x 1000baseTX (LAN)

          1 Reply Last reply Reply Quote 0
          • J
            jamesdean last edited by

            No biggy, sounds like the manual download rules code needs to be mirrored with the auto rules code.
            I be on that in a bit.

            Thnks
            James

            @DigitalJer:

            @jamesdean:

            Does snort stop after auto updates or does does snort stop after a few minutes of start ?

            It seems to quit after a few hours or more, not sure.  Not sure if it's actually stopping and cant' restart after the auto-updates, that's just a hunch.  I just know that when I check it on a daily basis, it's usually stopped.  I can re-start the service from the webgui OK.  Manually updating the rules also seems to restart the service OK.

            Now that I've done that for today, I know that by tomorrow the SNORT service will be in a Stopped status.

            Sorry if that wasn't clear the first time :(

            1 Reply Last reply Reply Quote 0
            • D
              DigitalJer last edited by

              @jamesdean:

              Thnks
              James

              No worries, and thank YOU!!

              –------------------------------------------------
              2.4.3-RELEASE (amd64)
              built on Mon Mar 26 18:02:04 CDT 2018
              FreeBSD 11.1-RELEASE-p7
              VM in ESXi 5.5
              1 x 1000baseTX (WAN)
              1 x 1000baseTX (LAN)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post