Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issues with Snort on 2.0

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    6 Posts 3 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Cino
      last edited by

      Not sure if this should go here or Packages… I made the jump to 2.0 with my new hardware and i'm able to get snort to install, download rules, and start with not issues.. But once I reboot, snort wont start and I get this in the system log that the user account for snort is unknown.. Any ideas?

      SnortStartup[27957]: Snort HARD Reload For 5687_em1…
      snort[27906]: FATAL ERROR: User "snort" unknown.
      snort[27906]: FATAL ERROR: User "snort" unknown.

      1 Reply Last reply Reply Quote 0
      • G
        grandrivers
        last edited by

        reload the newest snort and it should be fixed

        pfsense plus 25.03 super micro A1SRM-2558F
        C2558 32gig ECC  60gig SSD

        1 Reply Last reply Reply Quote 0
        • C
          Cino
          last edited by

          reload as in re-install the package? Was a fix applied since my post from yesterday? Also note, i'm using snapshot from 3-31. I would use the lastest one but need upnp services for some devices.

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            It was fixed in the package yesterday, reinstall Snort.

            1 Reply Last reply Reply Quote 0
            • C
              Cino
              last edited by

              that did the trick!! thank you!! ;D

              1 Reply Last reply Reply Quote 0
              • C
                Cino
                last edited by

                I think I see a bug with the auto blocker in Snort.. Correct me if i'm wrong here. If snort auto blocks an IP because of of a rule trigger, should I still see the IP being blocked in the firewall log?

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.