Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't Remove / Re-install Snort

    Scheduled Pinned Locked Moved pfSense Packages
    24 Posts 4 Posters 7.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bmeeksB
      bmeeks
      last edited by

      @BBcan177:

      @rcampbell:

      08-14-14 14:19:01 [ There were error(s) loading the rules: /tmp/rules.debug:24: cannot define table bogonsv6: Cannot allocate memory - The line in question reads [24]: table persist file /etc/bogonsv6]

      This error is related to the Max Table Entry Size in pfSense.

      You can increase the size of the table in:

      System:Advanced:Firewall/NAT:  Firewall Maximum Table Entries

      Maximum number of table entries for systems such as aliases, sshlockout, snort, etc, combined. Note: Leave this blank for the default.

      That may fix that particular error, but with only 256 MB of RAM more troubles will likely follow if you use Snort or Suricata or other memory-intensive packages.

      Bill

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        @bmeeks:

        That may fix that particular error, but with only 256 MB of RAM more troubles will likely follow if you use Snort or Suricata or other memory-intensive packages.

        Yes that is a definite issue…. Need atleast 3-4GB at minimum....

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • R
          rcampbell
          last edited by

          I have sorted the hardware issue for now.  I exported the config from the Alix, created a new pfSense VM and imported the config.  The difference is night and day, it is so much faster working with the GUI and adding or removing packages.

          I still seem to have one lingering problem though.  Some websites still seem to be blocked, or, certain elements of the page are blocked (such as banner adds etc) even though Snort is removed.

          My question now is; what is the config file that holds the list of IP's being blocked and where is it located.  I want to flush this out so I can start Snort from scratch.

          1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator
            last edited by

            There is a table called "Snort2c" which you can see in Diagnostics:Tables

            If the file is there, you can open it and click the "all" icon at the bottom to clear it.

            If Snort is installed, you can clear the table by going to the Snort:Blocked Tab and hitting the "Clear" Icon.

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.