Cannot check flow connection for non-TCP traffic
It means your snort rules or snort.conf file is NOT of the same version of snort you installed. Check which snort version you have like this:
snort -v
make sure that is you have oinkmaster installed make sure that your url is reflecting the correct rules file to download and oinkcode. You must first register with snort.org to receive an oinkcode.
Then just do this to update your rules, notice the dot:
cd /etc/snort/rules && oinkmaster -o .
or place into a cron for auto update of snort rules. Hope this saves someone a couple hours. -A
No comments:
Post a Comment