It seems that snort-dev shuts down on the first alert after an automatic rule update. I observed that at leats twice.
Here's the log:
Jun 29 00:10:07 gatekeeper snort[62591]: FATAL ERROR: s2c_pf_block() => ioctl() DIOCRADDADDRS: Bad file descriptor
Jun 29 00:10:07 gatekeeper kernel: em1: promiscuous mode disabled
I was testing whitelist changes today and enabled blocking, I'm seeing the same issues.
Is there an issue with the pf patch that was applied?
Jul 4 08:28:56 snort[4839]: FATAL ERROR: s2c_pf_block() => ioctl() DIOCRADDADDRS: Inappropriate ioctl for device
Jul 4 08:28:56 snort[4839]: FATAL ERROR: s2c_pf_block() => ioctl() DIOCRADDADDRS: Inappropriate ioctl for device