1. Dashboard
  2. Articles
  3. Forum
    1. Unresolved Threads
  4. Members
    1. Recent Activities
    2. Users Online
  5. Community vs. Enterprise
  • Login
  • Register
  • Search
This Thread
  • Everywhere
  • This Thread
  • This Forum
  • Articles
  • Forum
  • Pages
  • More Options
  1. efw-forum - Endian Firewall Support Forum
  2. Forum
  3. Archiv
  4. Endian Firewall 2.2
  5. weitere Services

Snort (Intrusion Detection System) FAILED

  • yuex
  • April 28, 2009 at 12:20 PM
  • Thread is Resolved
1st Official Post
  • yuex
    Beginner
    Posts
    5
    • April 28, 2009 at 12:20 PM
    • #1

    Snort (Intrusion Detection System) not working...

    /etc/init.d/snort restart FAILED



    How to fix

    Thanks

  • ffischer
    Moderator
    Reactions Received
    18
    Trophies
    1
    Articles
    8
    Posts
    2,415
    • April 28, 2009 at 12:31 PM
    • Official Post
    • #2

    Need some more information

    maybe if exist, post the Logfile /var/log/snort

    greets

    Endian Authorized Partner

    freaky-media
    Kein Support per PN dafür ist das Forum da.
    Preisanfragen zur Appliance Produkten sind über freaky-media möglich.

    • Next Official Post
  • yuex
    Beginner
    Posts
    5
    • April 28, 2009 at 12:49 PM
    • #3

    /var/log/snort/snort.log.1240849907

    http://rapidshare.com/files/226680475/snort.log.rar


    Thank you very much

  • ffischer
    Moderator
    Reactions Received
    18
    Trophies
    1
    Articles
    8
    Posts
    2,415
    • April 28, 2009 at 12:56 PM
    • Official Post
    • #4

    Cant read file correct.

    Code
    ÔÃ??          ê     ûÝõI&U >   >   E  >Á@ ~
    ?
    P?,Ï~e'µzÌ? =Õð?PÿTµ_  ã   X5	1?Xz,óç?aÝÅO>üÝõIX? >   >   E  >Ý@ ~
    ?
    P?,Ï~e'µzÌ? =ÕðþPÿ
    µR  ã   O5	1?Xz,óç?aÝÅO>þÝõIh >   >   E  >)@ ~
    o

    please Post var/log/snort "alert" file and var/log/messages

    Endian Authorized Partner

    freaky-media
    Kein Support per PN dafür ist das Forum da.
    Preisanfragen zur Appliance Produkten sind über freaky-media möglich.

    • Previous Official Post
    • Next Official Post
  • yuex
    Beginner
    Posts
    5
    • April 28, 2009 at 1:02 PM
    • #5

    okey

    http://rapidshare.com/files/226684683/endian.rar

  • ffischer
    Moderator
    Reactions Received
    18
    Trophies
    1
    Articles
    8
    Posts
    2,415
    • April 28, 2009 at 1:10 PM
    • Official Post
    • #6

    think you have a problem with your Firewall

    much entrys with

    Code
    Apr 28 06:19:12 firewall syslog-ng[1235]: Error opening file for writing; filename='/var/log/firewall', error='Is a directory (21)'

    Check your snort Config,
    uncheck all Network and try to use only "red"

    what kind of firewall Appliance .. Ccommunity ? Wich version?

    Endian Authorized Partner

    freaky-media
    Kein Support per PN dafür ist das Forum da.
    Preisanfragen zur Appliance Produkten sind über freaky-media möglich.

    • Previous Official Post
    • Next Official Post
  • yuex
    Beginner
    Posts
    5
    • April 28, 2009 at 1:39 PM
    • #7

    Endian Firewall Community release 2.2.rc3

    not working again

    I am send to snort.conf

  • ffischer
    Moderator
    Reactions Received
    18
    Trophies
    1
    Articles
    8
    Posts
    2,415
    • April 28, 2009 at 1:42 PM
    • Official Post
    • #8

    on wich Network you have snort enabled ?
    on all.
    maybe try to check if any interface do this Problem.

    Endian Authorized Partner

    freaky-media
    Kein Support per PN dafür ist das Forum da.
    Preisanfragen zur Appliance Produkten sind über freaky-media möglich.

    • Previous Official Post

Unterstützt von

  1. Privacy Policy
  2. Legal Notice
Powered by WoltLab Suite™