Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
Packages
»
Problem SNORT 2.9.1 pkg v. 2.1
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages:
1
2
[
3
]
4
5
Go Down
« previous
next »
Print
Author
Topic: Problem SNORT 2.9.1 pkg v. 2.1 (Read 7179 times)
0 Members and 1 Guest are viewing this topic.
trvsecurity
Newbie
Offline
Posts: 21
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #30 on:
January 26, 2012, 10:16:25 pm »
I have no idea how to see a cron job in PFSENSE (Im a Windows guy lol) - I activated SSH and tried to telnet on port 22 but I get a PROTOCOL MISMATCH error and no chance to login. How do I see cron jobs? lol
Logged
Cino
Hero Member
Offline
Posts: 1005
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #31 on:
January 26, 2012, 10:22:32 pm »
@dwood my statement was correct..... the green are new and red is whats deleted... in this case, you want to go back so it would be the opposite.
@torsurfer i've seen this before, cant remember the fix... did you update your rules? you have to update them for every re-install
@trvsecurity i've a windows guy too but knowledge is power..lol... telenet client wont work since its SSH... search for putty.. great tool and also winscp. install the Cron package, add a menu to see it in the web interface.
Logged
torsurfer
Newbie
Offline
Posts: 5
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #32 on:
January 26, 2012, 10:52:09 pm »
@cino You're right. Re-downloading the rules fixed the problem. Thanks!
Logged
mdima
Sr. Member
Offline
Posts: 364
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #33 on:
January 27, 2012, 02:01:21 am »
Hi,
I don't understand why you can specify which IP to block (src, dst, both) only if your HomeNet is a "whitelists" and not a "netlist".
Can you pls tell me the reason?
I see the "Which ip to block" select empty... Anyway, in this case what happens?
Thanks,
Michele
Logged
ermal
Administrator
Hero Member
Offline
Posts: 3094
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #34 on:
January 27, 2012, 03:06:32 am »
Quote from: Cino on January 26, 2012, 08:37:36 pm
binaries seem to be in but there are some issues..
@emarl The GUI doesn't have anything for the "Which ip to block" field under If Setting. Going to see if I can manually edit the conf file and see if I can get it to start when i have block offenders enabled.
Again is ermal.
Fixed.
Logged
ccb056
Full Member
Offline
Posts: 102
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #35 on:
January 27, 2012, 03:09:09 am »
is it safe to use the gui package management to upgrade now?
Logged
mdima
Sr. Member
Offline
Posts: 364
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #36 on:
January 27, 2012, 04:12:48 am »
Quote from: ermal on January 27, 2012, 03:06:32 am
Quote from: Cino on January 26, 2012, 08:37:36 pm
binaries seem to be in but there are some issues..
@emarl The GUI doesn't have anything for the "Which ip to block" field under If Setting. Going to see if I can manually edit the conf file and see if I can get it to start when i have block offenders enabled.
Again is ermal.
Fixed.
Hi Ermal,
thanks for fixing. Unfortunately now when I start the service I get the errors:
FATAL ERROR: pf.conf => Table snort2c,src,kill don't exists in packet filter
or
FATAL ERROR: pf.conf => Table snort2c,dst,kill don't exists in packet filter
or
FATAL ERROR: pf.conf => Table snort2c,both,kill don't exists in packet filter
depending on what option I set in the "Which ip to block" field of the interface...
Thanks,
Michele
Logged
mdima
Sr. Member
Offline
Posts: 364
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #37 on:
January 27, 2012, 04:14:26 am »
Quote from: ccb056 on January 27, 2012, 03:09:09 am
is it safe to use the gui package management to upgrade now?
I would wait a while.... I am doing my test on my secondary machine and I am having some trouble...
Logged
ermal
Administrator
Hero Member
Offline
Posts: 3094
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #38 on:
January 27, 2012, 04:30:03 am »
mdima,
EDIT: it seems you nave installed old binary still on your system that is why you get the error
«
Last Edit: January 27, 2012, 04:37:56 am by ermal
»
Logged
mdima
Sr. Member
Offline
Posts: 364
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #39 on:
January 27, 2012, 04:38:03 am »
Quote from: ermal on January 27, 2012, 04:30:03 am
mdima,
your options tells that you do not have a table snort2c defined in your filter rules.
Which should be by default hardcoded on pfSense rules.
Can you check on /tmp/rules.debug that there is a <snort2c> table defined?
Hi Ermal,
thanks for your prompt answer.
The table is defined in /tmp/rules.debug ("table <snort2c>" at line 15) and I can also see it in the Diagnostic->Tables page...
Thanks,
Michele
Logged
mdima
Sr. Member
Offline
Posts: 364
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #40 on:
January 27, 2012, 05:48:11 am »
Quote from: ermal on January 27, 2012, 04:30:03 am
mdima,
EDIT: it seems you nave installed old binary still on your system that is why you get the error
yes, even updating the package didn't help. So I removed then reinstalled the package and now everything seems to work... I will update my primary machine now and test it in deep!
Thanks,
Michele
Logged
ermal
Administrator
Hero Member
Offline
Posts: 3094
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #41 on:
January 27, 2012, 05:51:24 am »
There are 2 buttons there for re-installing a package.
One just installs the php code and the other updates the binaries as well.
I can only assume that you clicked the wrong button.
Logged
mdima
Sr. Member
Offline
Posts: 364
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #42 on:
January 27, 2012, 05:55:23 am »
Quote from: ermal on January 27, 2012, 05:51:24 am
There are 2 buttons there for re-installing a package.
One just installs the php code and the other updates the binaries as well.
I can only assume that you clicked the wrong button.
mmhhh... no, I pressed the "full reinstall" ("pkg icon"), not only the "interface" ("xml icon"), I am pretty sure because I did it twice after your message and I verified that pfSense didn't download the binary files...
Logged
dwood
Jr. Member
Offline
Posts: 77
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #43 on:
January 27, 2012, 08:28:16 am »
Thanks again to Ermal, Cino and Catfish. I learned a lot more about pfsense, particularly github and the code update process this time around :-)
I removed, then reinstalled (with settings saved) and everything seems to be working well. As always, rules must be updated after an update...no issues there. I've enabled "block offenders" "Kill states" and Block "SRC" and everything fired up (including a full set of rules) just fine. Version is AMD64, PF 2.0.1
Cheers,
Dennis.
Logged
darklogic
Full Member
Offline
Posts: 167
Re: Problem SNORT 2.9.1 pkg v. 2.1
«
Reply #44 on:
January 27, 2012, 08:36:21 am »
Ok, so before when I updated, I could not get snort to start after I selected block offenders, after updating again, I was able to get snort to start with block offenders checked, but now when I select any category, even if I select 1 freaking category, save and then try to restart snort, it will not start. "WTF" Thank God I have an Untangle system on the backend doing IPS.
Logged
Pages:
1
2
[
3
]
4
5
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...