Snort issue with cat. emerging-netbios.rules
-
Hi,
What might be the problem with categorie "emerging-netbios.rules"? I narrowed down that WITH this cat. enabled Snort on my Dell server won't start whatsoever…. Even when disabling 10 other categories won't help.
Server:
- Dell T110 4Gb i3 CPU 530 / Pfsense 1.2.3 / 1+4 Intel Gbit-nic's (lan,wan,DMZ1,DMZ2,WLAN)
PF Packages:
Backup, cron, dashboard, OpenVPNstatus, and Snort 2.8.6.1 pkg v. 1.34/1.35? (newest)Snort config:
- Installed Emergingthreats rules and Oinkmaster code
- just one interface added to snort, WAN with ACS performance
- added all categories, except emerging-netbios.rules.
- All Preprocessors enabled
- Servers and barnyard is empty/disabled (for now)
- Suppress is empty
- INSTALLED SIGNATURE RULESET
SNORT.ORG >>> N/A
EMERGINGTHREATS.NET >>> N/A
PFSENSE.ORG >>> 102
(Some days back I had the first 2 signatures as well...some hashcode and a 4-digit-no.)
-
Mmm… might has to do with this:... (???)
http://redmine.pfsense.org/projects/pfsense-packages/repository/revisions/e4352e9638d14a3bf2a36a71b1df6376b2ce703c