Fix for the latest snort version - Snort 2.9.1 pkg v. 2.0.2 ..anyone?



  • not too long ago snort was working just fine…then an update happened. i dont know the exact day, but it will no long run. the latest/last error in syslog is the following: **snort_exploit.rules(323) *PortVar Lookup failed on '$FILE_DATA_PORTS'.     >:(
    i would REALLY not like to do a hard code 'fix' to some config file, and i would love to know if this issue will be fixed anytime soon.

    it happens on both of my boxes (exact same hardware config) setup as active/passive failover via CARP.

    it is extremely frustrating. any insight/help would be nice. thank you in advance.

    FYI: the release i am using on both boxes is: 2.0.1-RELEASE (i386) built on Tue Dec 13 13:35:17 EST 2011 FreeBSD 8.1-RELEASE-p6



  • Before hard coding, you can start reading forum topics to see if isn't already posted

    http://forum.pfsense.org/index.php/topic,44489.msg230969.html#msg230969

    It is extremely frustrating see the same question just five posts from original thread too.



  • and yet its still a hard code 'fix' that works partially. so thank you SOOO much for the sarcastic help there.  :(



  • oh, and said category has never been selected. ….so..ummm...kay



  • Why you do not contribute to pfSense for keeping snort up-to date as you do for snort.org?



  • well its not my 'specialty' and i am still learning. i am all for contributing in anyway that i can, and right now ..that is doing a lot of research so i can actually learn more about the environment as a whole. ..which i love..

    so..if you took my questions or comments as being snippy or what not…i apologize, but a person has to start somewhere. we all cant be 100% knowledgeable over night.  :-[


Locked