• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Snort configuration problems

Scheduled Pinned Locked Moved pfSense Packages
6 Posts 3 Posters 2.7k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • H
    heiko
    last edited by Mar 30, 2007, 1:18 PM Mar 30, 2007, 1:02 PM

    hello,

    i have installed the snort package, the service looks fine, i configured it and set snort to hear on the LAN and WAN-Interface. I test it with Nessus, but nothing happens…. From the console menue i started snort manually and snort logs a "compilation failure".

    A configuration failure? i am running the newest releng_snapshot.
    Greetings
    heiko
    errors.jpg
    errors.jpg_thumb
    lan-config.jpg
    lan-config.jpg_thumb
    logfile.jpg
    logfile.jpg_thumb
    services.jpg
    services.jpg_thumb
    snort-config.jpg
    snort-config.jpg_thumb

    1 Reply Last reply Reply Quote 0
    • B
      Brian_Andle
      last edited by Mar 30, 2007, 2:36 PM Mar 30, 2007, 2:19 PM

      Correct me if I'm wrong but Snort should only be attached to lan, you want to block bad stuff coming in not your internal computers going out.

      Also if you are not using carp, uncheck the last option.

      1 Reply Last reply Reply Quote 0
      • H
        heiko
        last edited by Mar 30, 2007, 2:39 PM

        Ups, the description says "Select all WAN type interfaces". I´m confused but i will test it.

        1 Reply Last reply Reply Quote 0
        • B
          Brian_Andle
          last edited by Mar 30, 2007, 2:45 PM

          WAN is the network card that connects to the internet. LAN is the card the connects to the internal network. Snort detects and if enabled blocks computers from the internet (wan) attempting to connect to your computers (lan).

          1 Reply Last reply Reply Quote 0
          • Y
            yoda715
            last edited by Mar 30, 2007, 7:16 PM

            For the moment, snort can only be applied to one WAN interface.

            1 Reply Last reply Reply Quote 0
            • H
              heiko
              last edited by Mar 30, 2007, 7:47 PM

              yes, OK, i have tested it , for the initial start of snort after a complete reset to pfsense all works fine and the log is full. If i changed anything, for example "wan to lan" and back, the snort package is a little bit confused.

              The Service is started, but nothing happens, no logs… If i went "nessus" against the wan interface, nothing happens again.

              I don´t know, i think the package is not really clean, but maybe my test was incorrect...

              1 Reply Last reply Reply Quote 0
              3 out of 6
              • First post
                3/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received