Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort not working?

    Scheduled Pinned Locked Moved pfSense Packages
    12 Posts 5 Posters 6.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      Bai Shen
      last edited by

      I have snort installed and with almost all of the rules turned on except for chat and p2p.  It shows as running in the gui, and I see the process in top.  But I'm not getting any alerts or blocks.  I find this hard to believe, as when I was previously running snort, I was getting at least a couple hits a day.

      Is there something in the setup I need to change or check?  How can I tell it's working correctly?

      1 Reply Last reply Reply Quote 0
      • L
        LostInIgnorance
        last edited by

        What interface is it running on?

        1 Reply Last reply Reply Quote 0
        • B
          Bai Shen
          last edited by

          @LostInIgnorance:

          What interface is it running on?

          WAN

          1 Reply Last reply Reply Quote 0
          • L
            LostInIgnorance
            last edited by

            Can you give a bit of info about your network setup? (asci/paint diagram would be nice)

            1 Reply Last reply Reply Quote 0
            • B
              Bai Shen
              last edited by

              Not to be difficult, but what does that have to do with snort picking up things from the internet?

              1 Reply Last reply Reply Quote 0
              • L
                LostInIgnorance
                last edited by

                If you have something before the pfsense, sometimes the modems associated with dsl/cable have firewalls naturally enabled on them.

                1 Reply Last reply Reply Quote 0
                • B
                  Bai Shen
                  last edited by

                  @LostInIgnorance:

                  If you have something before the pfsense, sometimes the modems associated with dsl/cable have firewalls naturally enabled on them.

                  Just the same Moto 6120 I've been running previously.

                  1 Reply Last reply Reply Quote 0
                  • M
                    mantic
                    last edited by

                    I have the same issue… I may just build the damn thing by hand... it seems that it doesn't pick up EXTERNAL and INTERNAL net...

                    1 Reply Last reply Reply Quote 0
                    • J
                      jamesdean
                      last edited by

                      @mantic:

                      I have the same issue… I may just build the damn thing by hand... it seems that it doesn't pick up EXTERNAL and INTERNAL net...

                      @mantic

                      Do us a favor.

                      Post you system spec, network map and any setting that might affect snort.

                      Rob

                      1 Reply Last reply Reply Quote 0
                      • B
                        Bai Shen
                        last edited by

                        So, I went to GRC and did a port scan on my ip.  Still nothing from Snort.  I'm beginning to wonder if it's even running.

                        What can I look at in order to tell if things are working correctly?

                        1 Reply Last reply Reply Quote 0
                        • _
                          _igor_
                          last edited by

                          when snort starts up, it fills the whole systemlog with messages. The last ones should be like this:

                          snort[62829]: Snort initialization completed successfully (pid=62829)
                          Mar 25 00:02:18	snort[62829]: Snort initialization completed successfully (pid=62829)
                          Mar 25 00:02:18	snort[62829]: --== Initialization Complete ==--
                          Mar 25 00:02:18	snort[62829]: --== Initialization Complete ==--
                          
                          1 Reply Last reply Reply Quote 0
                          • B
                            Bai Shen
                            last edited by

                            Yeah, it turned out I had to turn on the preprocessors.

                            BTW, it lists an option for collecting performance statistics, but I couldn't find where they're collected.  Any ideas?

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.