Snort: Another solution to the rule enable/disable update reset problem
-
Thanks for the clarification. I still had the old directories from the previous (2.5.4) installation and I was looking there. That brought some confusion. I uninstalled snort again, removed old directories and installed it again.
You are doing a good job!
Yeah, one of the things I added in this latest update was to try and do a better job of "cleaning up" when uninstalling. Of course for the initial update from 2.5.4, or any earlier version, to 2.5.5, you will potentially have to do some manual clean up. After that Snort should be a little better cleaning up. It will leave some directories in the old locations, but they should be empty of files.
For 2.0.x pfSense users, the Snort files are still in /usr/local/etc/snort. But for 2.1 pfSense users, everything now will be in /usr/pbi/snort-{arch}/etc/snort where {arch} is either i386 or amd64, depending on your platform.
Bill