Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
[SOLVED] snort rules
« previous
next »
Print
Pages: [
1
]
Author
Topic: [SOLVED] snort rules (Read 13803 times)
Rout3rx
Newbie
Posts: 38
Karma: 1
[SOLVED] snort rules
«
on:
October 29, 2017, 08:17:09 pm »
hello
i updated opnsense and saw the snort compatible rules appear, i setup the plugin but i cannot install the rules which is appear in Downloads tab in intrusion system.
what can i do?
i saw a path this file:
snortrules-snapshot-2990.tar.gz
what is it?
«
Last Edit: October 30, 2017, 09:31:03 am by franco
»
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: snort rules
«
Reply #1 on:
October 29, 2017, 08:24:21 pm »
It's a mock default value, you need the proper one and oink code anyway:
https://github.com/opnsense/plugins/blob/master/security/intrusion-detection-content-snort-vrt/src/opnsense/scripts/suricata/metadata/rules/snort-vrt.xml#L126
You find the settings underneath the download tab underneath the rules:
snort_vrt.oinkcode
snort_vrt.rulesfile
As described in
https://www.snort.org/oinkcodes
Cheers,
Franco
Logged
Rout3rx
Newbie
Posts: 38
Karma: 1
Re: snort rules
«
Reply #2 on:
October 29, 2017, 08:26:24 pm »
i set the oinkcode and try to download but nothing downloaded
«
Last Edit: October 29, 2017, 08:38:05 pm by Rout3rx
»
Logged
Rout3rx
Newbie
Posts: 38
Karma: 1
Re: snort rules
«
Reply #3 on:
October 29, 2017, 08:47:43 pm »
thanks, it's goes to download after some seconds.
Logged
peter008
Newbie
Posts: 31
Karma: 3
Re: [SOLVED] snort rules
«
Reply #4 on:
January 06, 2019, 07:59:00 am »
Where do I find the snort-vrt.xml file actually to paste the Oinkcode?
I did not find it under /usr/local/opnsense/scripts/suricata/metadata/rules .
«
Last Edit: January 06, 2019, 08:01:46 am by peter008
»
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: [SOLVED] snort rules
«
Reply #5 on:
January 06, 2019, 09:01:48 pm »
Services: Intrusion Detection: Administration: Tab "Download" at the bottom:
snort_vrt.oinkcode
snort_vrt.rulesfile
Cheers,
Franco
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: [SOLVED] snort rules
«
Reply #6 on:
January 06, 2019, 09:02:26 pm »
PS: Don't forget to install the os-intrusion-detection-content-snort-vrt plugin....
Logged
peter008
Newbie
Posts: 31
Karma: 3
Re: [SOLVED] snort rules
«
Reply #7 on:
January 10, 2019, 10:22:09 am »
Ah, ok, I did not know this plugin yet (came from pfsense where it does not exist).
Works now.
Thanks a lot.
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: [SOLVED] snort rules
«
Reply #8 on:
January 10, 2019, 10:49:14 am »
Ah great, no problem
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
[SOLVED] snort rules