0000583Endian FirewallOther Servicespublic2008-03-03 11:292009-10-27 12:03
0000583: Snort Rules Location Incorrect?
It could be me and my misunderstanding of snort so please forgive me if the issue is really not an actual issue. Looking at the /etc/snort/snort.conf.tmpl on line 29 "var RULE_PATH /etc/snort/rules" seems to be incorrect. Shouldn't it be "var RULE_PATH /etc/snort" as the current rules folder does exist but is completly empty. The snort rules are being downloaded to /etc/snort and are there and have a .rules extension. The rules were downloaded by EFW web interface (services-intrusion detection-download new ruleset). In addition, shouldn't the snort.conf.tmpl include a section similiar to this:

##Customize your rule set
include $RULE_PATH/local.rules
include $RULE_PATH/bad-traffic.rules
include $RULE_PATH/exploit.rules

Thanks for a great product once the bugs are worked out.
No tags attached.
Issue History
2008-03-03 11:29BKJNew Issue
2008-03-04 15:12peter-endianStatusnew => confirmed
2008-03-04 15:13peter-endianRelationship addedrelated to 0000536
2008-05-09 17:50peter-endianRelationship addedrelated to 0000732
2008-05-09 17:50peter-endianStatusconfirmed => resolved
2008-05-09 17:50peter-endianFixed in Version => 2.2-rc1
2008-05-09 17:50peter-endianResolutionopen => fixed
2008-05-09 17:50peter-endianAssigned To => peter-endian
2009-10-27 12:03peter-endianStatusresolved => closed

