Fatal Error Starting Snort



  • Hello, I am getting an error when starting snort on my pfsense home installation.  The error is as follows.

    FATAL ERROR: /usr/local/etc/snort/snort_41876_re1/rules/snort.rules(9) Unknown ClassType: protocol-command-decode

    I was not getting any errors until May 13th, then suddenly this started.  It appears is it failing on reading a rule when snort starts, but I have no idea how to clear this out.  Any suggestions?

    Joe



  • @joemamasmac:

    Hello, I am getting an error when starting snort on my pfsense home installation.  The error is as follows.

    FATAL ERROR: /usr/local/etc/snort/snort_41876_re1/rules/snort.rules(9) Unknown ClassType: protocol-command-decode

    I was not getting any errors until May 13th, then suddenly this started.  It appears is it failing on reading a rule when snort starts, but I have no idea how to clear this out.  Any suggestions?

    Joe

    The failing rule is on line #9 in the file given in the error message.  Open that file and look at line 9 for the offending rule.  Have you fiddled with any of the preprocessor settings on the PREPROCESSORS tab?  Fiddling with preprocessors (as in disabling some of them that are enabled by default) without a total and complete knowledge of what each one is for frequently results in this kind of error.  Not saying a rule vendor cannot make a mistake now and then, but the most common cause of errors like yours is when someone has turned off a required preprocessor.

    Bill


Log in to reply