From 71a3b727a3121c2bd081fe1f657f9dbe563e7064 Mon Sep 17 00:00:00 2001 From: robiscool Date: Wed, 30 Sep 2009 03:25:18 -0700 Subject: Push snort 1.6 to stable, fix some startup issues --- config/snort/snort.xml | 142 +++++++++++++++++++++++++++++++++++++------------ 1 file changed, 109 insertions(+), 33 deletions(-) (limited to 'config/snort/snort.xml') diff --git a/config/snort/snort.xml b/config/snort/snort.xml index f8e35c28..2370be0e 100644 --- a/config/snort/snort.xml +++ b/config/snort/snort.xml @@ -46,8 +46,8 @@ Describe your package requirements here Currently there are no FAQ items provided. Snort - 2.8.4.1 - Services: Snort 2.8.4.1 pkg v. 1.5 + 2.8.4.1_1 + Services: Snort 2.8.4.1_2 pkg v. 1.6 /usr/local/pkg/snort.inc Snort @@ -59,6 +59,7 @@ snort snort.sh snort + Snort is the most widely deployed IDS/IPS technology worldwide.. @@ -106,82 +107,87 @@ /usr/local/pkg/ 077 - http://www.pfsense.com/packages/config/snort/snort.inc + http://www.pfsense.com/packages/config/snort-dev/snort.inc /usr/local/bin/ 077 - http://www.pfsense.com/packages/config/snort/bin/snort2c + http://www.pfsense.com/packages/config/snort-dev/bin/barnyard2 /usr/local/bin/ 077 - http://www.pfsense.com/packages/config/snort/bin/oinkmaster_contrib/create-sidmap.pl + http://www.pfsense.com/packages/config/snort-dev/bin/oinkmaster_contrib/create-sidmap.pl /usr/local/bin/ 077 - http://www.pfsense.com/packages/config/snort/bin/mons2c - + http://www.pfsense.com/packages/config/snort-dev/bin/oinkmaster_contrib/oinkmaster.pl + /usr/local/www/ 077 - http://www.pfsense.com/packages/config/snort/snort_download_rules.php + http://www.pfsense.com/packages/config/snort-dev/snort_download_rules.php /usr/local/www/ 077 - http://www.pfsense.com/packages/config/snort/snort_rules.php + http://www.pfsense.com/packages/config/snort-dev/snort_rules.php /usr/local/www/ 077 - http://www.pfsense.com/packages/config/snort/snort_rules_edit.php + http://www.pfsense.com/packages/config/snort-dev/snort_rules_edit.php /usr/local/www/ 077 - http://www.pfsense.com/packages/config/snort/snort_rulesets.php + http://www.pfsense.com/packages/config/snort-dev/snort_rulesets.php /usr/local/pkg/ 077 - http://www.pfsense.com/packages/config/snort/snort_whitelist.xml + http://www.pfsense.com/packages/config/snort-dev/snort_whitelist.xml /usr/local/www/ 077 - http://www.pfsense.com/packages/config/snort/snort_blocked.php + http://www.pfsense.com/packages/config/snort-dev/snort_blocked.php /usr/local/pkg/ 077 - http://www.pfsense.com/packages/config/snort/snort_check_for_rule_updates.php + http://www.pfsense.com/packages/config/snort-dev/snort_check_for_rule_updates.php /usr/local/www/ 077 - http://www.pfsense.com/packages/config/snort/snort_alerts.php + http://www.pfsense.com/packages/config/snort-dev/snort_alerts.php + + + /usr/local/pkg/pf/ + 077 + http://www.pfsense.com/packages/config/snort-dev/snort_dynamic_ip_reload.php /usr/local/pkg/ 077 - http://www.pfsense.com/packages/config/snort/snort_dynamic_ip_reload.php + http://www.pfsense.com/packages/config/snort-dev/snort_advanced.xml /usr/local/pkg/ 077 - http://www.pfsense.com/packages/config/snort/snort_advanced.xml + http://www.pfsense.com/packages/config/snort-dev/snort_define_servers.xml /usr/local/pkg/ 077 - http://www.pfsense.com/packages/config/snort/snort_define_servers.xml + http://www.pfsense.com/packages/config/snort-dev/snort_threshold.xml /usr/local/pkg/ 077 - http://www.pfsense.com/packages/config/snort/snort_threshold.xml + http://www.pfsense.com/packages/config/snort-dev/pfsense_rules/local.rules @@ -194,7 +200,7 @@ true - Performance + Memory Performance performance Lowmem and ac-bnfa are recommended for low end systems, Ac: high memory, best performance, ac-std: moderate memory,high performance, acs: small memory, moderateperformance, ac-banded: small memory,moderate performance, ac-sparsebands: small memory, high performance. select @@ -246,16 +252,92 @@ Block offenders - blockoffenders + blockoffenders7 Checking this option will automatically block hosts that generate a snort alert. checkbox 60 + + Remove blocked hosts every + rm_blocked + Please select the amount of time hosts are blocked + select + + + + + + + + + + + + + + Update rules automatically - automaticrulesupdate - Checking this option will automatically check for and update rules once a week from snort.org. - checkbox + autorulesupdate7 + Please select the update times for rules. + select + + + + + + + + + Whitelist VPNs automatically @@ -275,12 +357,6 @@ Checking this option will automatically associate the blocked reason from the snort alerts file. checkbox - - Sync Snort configuration to secondary cluster members - syncxmlrpc - Checking this option will automatically sync the snort configuration via XMLRPC to CARP cluster members. - checkbox - Install emergingthreats rules. emergingthreats @@ -288,15 +364,15 @@ checkbox - - sync_package_snort(); + + sync_package_snort_reinstall(); snort_deinstall(); - + \ No newline at end of file -- cgit v1.2.3