<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort - ET Rules not available for LAN interface]]></title><description><![CDATA[<p dir="auto">I have snort 2.9.0.5 pkg v. 2.0 on pfsense 2.0 release.  I've had it working fine on my WAN interface using both the ET and snort rules.  I recently started monitoring my LAN interface and it's working fine EXCEPT that for some reason I cannot seem to get the Emerging Threats categories available under the interface options.  All the snort rules show up fine and are working correctly, however the rules I really want to use on the LAN are in the ET categories.  I've tried updating the rules, recreating the interface monitor, disabling / enabling ET downloads and I still can't get it to show up.  I am at a loss here.  I can't find any logs giving me any errors or anything.</p>
<p dir="auto">Anybody have any ideas to maybe help point me in the right direction?</p>
]]></description><link>https://forum.netgate.com/topic/38320/snort-et-rules-not-available-for-lan-interface</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Jul 2026 15:55:00 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/38320.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 17 Oct 2011 23:05:46 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Snort - ET Rules not available for LAN interface on Thu, 20 Oct 2011 19:04:07 GMT]]></title><description><![CDATA[<p dir="auto">I had the same issue.  In the end, I decided I didn't need Snort running on my LAN interface. But I had a lot of weirdness getting the right rules in the right places, e.g. I had the same problem on my WAN interface too, on one of my pfSense 2.0 boxes, but not it's mirror copy. For the WAN interface I found the rules were in a subdir of the rules directory also called rules.  So I just copied everything in /usr/local/etc/snort/snort_XXXXX_XXX/rules/rules to /usr/local/etc/snort/snort_XXXXX_XXX/rules/ and then removed the subdirectory.  Seemed to work for me.  YMMV.  Sounds like a bug that can happen under some circumstances…</p>
<p dir="auto">P.S. Another solution to this or another problem (I forget how I solved each problem as there have been several) was to remove the md5 file for e.g. emerging.rules.tar.gz.md5 or snortrules-snapshot-2905.tar.gz.md5 and then run an update.  Then it will fetch a new copy of the rules and extract it.  Again, YMMV.</p>
<p dir="auto">Let me know if either of these work for you.</p>
]]></description><link>https://forum.netgate.com/post/301017</link><guid isPermaLink="true">https://forum.netgate.com/post/301017</guid><dc:creator><![CDATA[Seb]]></dc:creator><pubDate>Thu, 20 Oct 2011 19:04:07 GMT</pubDate></item></channel></rss>