OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • [SOLVED] snort rules
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] snort rules  (Read 13856 times)

Rout3rx

  • Newbie
  • *
  • Posts: 38
  • Karma: 1
    • View Profile
[SOLVED] snort rules
« on: October 29, 2017, 08:17:09 pm »
hello
i updated opnsense and saw the snort compatible rules appear, i setup the plugin but i cannot install the rules which is appear in Downloads tab in intrusion system.
what can i do?
i saw a path this file:
snortrules-snapshot-2990.tar.gz
what is it?
« Last Edit: October 30, 2017, 09:31:03 am by franco »
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: snort rules
« Reply #1 on: October 29, 2017, 08:24:21 pm »
It's a mock default value, you need the proper one and oink code anyway:

https://github.com/opnsense/plugins/blob/master/security/intrusion-detection-content-snort-vrt/src/opnsense/scripts/suricata/metadata/rules/snort-vrt.xml#L126

You find the settings underneath the download tab underneath the rules:

snort_vrt.oinkcode
snort_vrt.rulesfile

As described in https://www.snort.org/oinkcodes


Cheers,
Franco
Logged

Rout3rx

  • Newbie
  • *
  • Posts: 38
  • Karma: 1
    • View Profile
Re: snort rules
« Reply #2 on: October 29, 2017, 08:26:24 pm »
i set the oinkcode and try to download but nothing downloaded
« Last Edit: October 29, 2017, 08:38:05 pm by Rout3rx »
Logged

Rout3rx

  • Newbie
  • *
  • Posts: 38
  • Karma: 1
    • View Profile
Re: snort rules
« Reply #3 on: October 29, 2017, 08:47:43 pm »
thanks, it's goes to download after some seconds.
Logged

peter008

  • Newbie
  • *
  • Posts: 31
  • Karma: 3
    • View Profile
Re: [SOLVED] snort rules
« Reply #4 on: January 06, 2019, 07:59:00 am »
Where do I find the snort-vrt.xml file actually to paste the Oinkcode?

I did not find it under /usr/local/opnsense/scripts/suricata/metadata/rules .
« Last Edit: January 06, 2019, 08:01:46 am by peter008 »
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: [SOLVED] snort rules
« Reply #5 on: January 06, 2019, 09:01:48 pm »
Services: Intrusion Detection: Administration: Tab "Download" at the bottom:

snort_vrt.oinkcode   
snort_vrt.rulesfile


Cheers,
Franco
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: [SOLVED] snort rules
« Reply #6 on: January 06, 2019, 09:02:26 pm »
PS: Don't forget to install the os-intrusion-detection-content-snort-vrt plugin....
Logged

peter008

  • Newbie
  • *
  • Posts: 31
  • Karma: 3
    • View Profile
Re: [SOLVED] snort rules
« Reply #7 on: January 10, 2019, 10:22:09 am »
Ah, ok, I did not know this plugin yet (came from pfsense where it does not exist).

Works now.

Thanks a lot.
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: [SOLVED] snort rules
« Reply #8 on: January 10, 2019, 10:49:14 am »
Ah great, no problem :)
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • [SOLVED] snort rules
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2