Bug #3850
closedSnort "add a new interface based on this" creates a bad configuration
0%
Description
pfSense 2.1.5-RELEASE (amd64)
Snort 2.9.6.2 pkg v3.1.2
Using the "add a new interface based on this one" button causes the new interface to inherit the same -R argument to the snort command. This results in bad behaviour when shutting down/starting up.
For example, when starting cold, the first interface starts fine, but the next (created based on the first) is issued a soft restart for process that doesn't exist.
SnortStartup64120: Snort STOP WAN
SnortStartup6135: Snort SOFT RESTART for WAN2...
The workaround is to destroy the cloned interface and manually re-create it, and then everything is fine.
Updated by Braden Del More over 11 years ago
Apologies for not using /pre in my previous message.
SnortStartup[64120]: Snort STOP WAN(8409_ig2) SnortStartup[6135]: Snort SOFT RESTART for WAN2(8409_ig2)
Updated by Bill Meeks over 11 years ago
I am a volunteer maintainer for the Snort package on pfSense. Thank you for reporting this bug. It will be corrected in the next Snort package update.
Bill
Updated by Chris Buechler about 11 years ago
- Status changed from New to Feedback
Bill: was this fixed?