OPNsense Forum

English Forums => General Discussion => Topic started by: Rout3rx on October 29, 2017, 08:17:09 pm

Title: [SOLVED] snort rules
Post by: Rout3rx on October 29, 2017, 08:17:09 pm
hello
i updated opnsense and saw the snort compatible rules appear, i setup the plugin but i cannot install the rules which is appear in Downloads tab in intrusion system.
what can i do?
i saw a path this file:
snortrules-snapshot-2990.tar.gz
what is it?
Title: Re: snort rules
Post by: franco on October 29, 2017, 08:24:21 pm
It's a mock default value, you need the proper one and oink code anyway:

https://github.com/opnsense/plugins/blob/master/security/intrusion-detection-content-snort-vrt/src/opnsense/scripts/suricata/metadata/rules/snort-vrt.xml#L126

You find the settings underneath the download tab underneath the rules:

snort_vrt.oinkcode
snort_vrt.rulesfile

As described in https://www.snort.org/oinkcodes


Cheers,
Franco
Title: Re: snort rules
Post by: Rout3rx on October 29, 2017, 08:26:24 pm
i set the oinkcode and try to download but nothing downloaded
Title: Re: snort rules
Post by: Rout3rx on October 29, 2017, 08:47:43 pm
thanks, it's goes to download after some seconds.
Title: Re: [SOLVED] snort rules
Post by: peter008 on January 06, 2019, 07:59:00 am
Where do I find the snort-vrt.xml file actually to paste the Oinkcode?

I did not find it under /usr/local/opnsense/scripts/suricata/metadata/rules .
Title: Re: [SOLVED] snort rules
Post by: franco on January 06, 2019, 09:01:48 pm
Services: Intrusion Detection: Administration: Tab "Download" at the bottom:

snort_vrt.oinkcode   
snort_vrt.rulesfile


Cheers,
Franco
Title: Re: [SOLVED] snort rules
Post by: franco on January 06, 2019, 09:02:26 pm
PS: Don't forget to install the os-intrusion-detection-content-snort-vrt plugin....
Title: Re: [SOLVED] snort rules
Post by: peter008 on January 10, 2019, 10:22:09 am
Ah, ok, I did not know this plugin yet (came from pfsense where it does not exist).

Works now.

Thanks a lot.
Title: Re: [SOLVED] snort rules
Post by: franco on January 10, 2019, 10:49:14 am
Ah great, no problem :)