Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort Won't Start After Upgrade

    Scheduled Pinned Locked Moved pfSense Packages
    301 Posts 64 Posters 215.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      serialdie
      last edited by

      @Cino:

      @asterix:

      By any chance.. do you have the widescreen package installed?

      nope… Would like to use it but not till its fully completed

      Matthias did some changes to fix the issues with the widescreen pkg…

      http://forum.pfsense.org/index.php/topic,35285.0.html

      Though is a manual process and still requires some editing if you are not running 2.1... All in all it works and fixes a lot of bugs.

      1 Reply Last reply Reply Quote 0
      • B
        breusshe
        last edited by

        I personally consider it a bug since you don't normally think of your home net as your WAN interface.  I don't know how pfSense feels about that, which is what will ultimately decide if this is a "bug" or "feature".

        1 Reply Last reply Reply Quote 0
        • C
          Cino
          last edited by

          @Ermal I noticed you added some code to allow inspecting gzipped http flows.. After updating the package i'm receiving this error:

          snort[1781]: FATAL ERROR: /usr/local/etc/snort/snort_39737_em3/snort.conf(171) => Enable 'extended_response_inspection' inspection before setting 'inspect_gzip'

          i removed the changes from my box and snort started again.

          doing some research, i add extended_response_inspection before the changes you change and snort started. Based on the docs, this is needed for the inspect_gzip setting

          
          			extended_response_inspection \
          			inspect_gzip \
          			normalize_utf \
          			unlimited_decompress \
          
          

          Reviewing the different settings, think it would make sense have them under Preprocessors: HTTP Inspect Settings. With all the different settings available for snort, I can see why it would almost be a full-time job to make everything configurable within pfSense.

          P.S I still can't clear the alert log. After clicking 'OK' to clear the log, nothing happens. At least i'm not being directed to a blank page now.

          1 Reply Last reply Reply Quote 0
          • E
            eri--
            last edited by

            Thanks Cino for the usual help.

            The alert mostly works when it does not work its mostly because of snort reloading or php doing something stupid though i have not investigated which is that does this.

            1 Reply Last reply Reply Quote 0
            • C
              Cino
              last edited by

              Anytime!

              Looks like someone figured out a fix for clearing the alert log. Take a look when you have time, http://redmine.pfsense.org/issues/1765

              1 Reply Last reply Reply Quote 0
              • E
                eri--
                last edited by

                I just pushed the fixes for the alert.
                Test it out.

                1 Reply Last reply Reply Quote 0
                • C
                  Cino
                  last edited by

                  tested and confirm it is working.. Thanks again

                  1 Reply Last reply Reply Quote 0
                  • B
                    bdwyer
                    last edited by

                    How did you manage to update Snort with that fix?  Is it in a new ISO or must I place the new snort_alerts.php there manually?

                    CCNP, MCITP

                    Intel Atom N550 - 2gb DDR3
                    Jetway NC9C-550-LF
                    Antec ISK 300-150
                    HP ProCurve 1810-24
                    Cisco 1841 & 2821, Cisco 3550 x3

                    1 Reply Last reply Reply Quote 0
                    • marcellocM
                      marcelloc
                      last edited by

                      @bdwyer:

                      How did you manage to update Snort with that fix?  Is it in a new ISO or must I place the new snort_alerts.php there manually?

                      Basically, when you see updates in forum and no change in package version, just reinstall(in this case snort package) to get latest files version.

                      Treinamentos de Elite: http://sys-squad.com

                      Help a community developer! ;D

                      1 Reply Last reply Reply Quote 0
                      • B
                        bdwyer
                        last edited by

                        Yes, I think that worked.  Thanks for filling me in.

                        CCNP, MCITP

                        Intel Atom N550 - 2gb DDR3
                        Jetway NC9C-550-LF
                        Antec ISK 300-150
                        HP ProCurve 1810-24
                        Cisco 1841 & 2821, Cisco 3550 x3

                        1 Reply Last reply Reply Quote 0
                        • X
                          xieliwei
                          last edited by

                          Sorry for reviving an old thread, but I've been having the Unknown output plugin: "alert_pf" problem on my AMD64 pfSense 2.0 install.

                          I originally thought it could be a package problem; but after a few updates and apparently no one else has this problem anymore, I suspect I'm missing something.

                          Can anyone clarify if "Block offenders" is working on AMD64?

                          If so, any clues about why mine doesn't work?

                          1 Reply Last reply Reply Quote 0
                          • marcellocM
                            marcelloc
                            last edited by

                            did you tried to uninstall / reinstall snort package?

                            Treinamentos de Elite: http://sys-squad.com

                            Help a community developer! ;D

                            1 Reply Last reply Reply Quote 0
                            • X
                              xieliwei
                              last edited by

                              Yes, every single time.
                              Just in case, I did it again. No luck.

                              Pretty sure my messing around caused this, anyone knows which library contains the alert_pf plugin?

                              1 Reply Last reply Reply Quote 0
                              • marcellocM
                                marcelloc
                                last edited by

                                Try to uninstall again, then go ti console and remove any snort package or dependencie left behind.
                                I think some post on this topic has a detailed info about this.

                                Treinamentos de Elite: http://sys-squad.com

                                Help a community developer! ;D

                                1 Reply Last reply Reply Quote 0
                                • C
                                  cmb
                                  last edited by

                                  Locking this thread so it won't get hijacked over and over by numerous different issues, please start new threads instead.

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.