<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SolutionIn order to resolve in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snort-2-9-5-may-generate-an-error-if-local-rules-are-enabled/m-p/2554263#M925685</link>
    <description>&lt;H4&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/H4&gt;&lt;P&gt;In order to resolve this issue install SEU 915 or higher.&lt;/P&gt;&lt;H4&gt;&lt;BR /&gt;&lt;STRONG&gt;Root Cause&lt;/STRONG&gt;&lt;/H4&gt;&lt;P&gt;An issue has been identified with custom rules or Emerging Threat rules that can violate the Snort rule syntax. These rules can cause the Detection Engine to repeatedly restart. Sourcefire provided rules do not contain these syntax errors and will not cause this problem.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Snort does rule validation upon start up.&amp;nbsp; With Snort 2.9.4, when a rule is determined invalid, then a warning is written to syslog. However, Snort will continue to load omitting that rule.&amp;nbsp; The Snort delivered in SEU 913 generates an error for invalid rules instead of a warning, which prevents Snort from loading.&amp;nbsp; With the release of SEU 915, we simply made Snort 2.9.5 behave the same way Snort 2.9.4 does, which is to display a warning for invalid rules, but continue to load.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Invalid third party rule syntax is still an issue as SEU 915 will not correct them.&amp;nbsp; To make sure rules are valid you can simply open an IPS policy in the editor and save it, or manually apply the policy.&amp;nbsp; You will be notified if there are any invalid rules active in that policy.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jul 2014 17:26:15 GMT</pubDate>
    <dc:creator>Nazmul Rajib</dc:creator>
    <dc:date>2014-07-03T17:26:15Z</dc:date>
    <item>
      <title>Snort 2.9.5 may generate an error if local rules are enabled</title>
      <link>https://community.cisco.com/t5/network-security/snort-2-9-5-may-generate-an-error-if-local-rules-are-enabled/m-p/2554262#M925684</link>
      <description>&lt;P&gt;After installing SEU 913, which includes Snort 2.9.5, the following symptoms may appear in a Sourcefire deployment:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&amp;nbsp;The sensor may go down&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Unable to commit any changes to an IPS policy&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Health Alerts state that the IPS/IDS DE exited unexpectedly&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:13:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort-2-9-5-may-generate-an-error-if-local-rules-are-enabled/m-p/2554262#M925684</guid>
      <dc:creator>Nazmul Rajib</dc:creator>
      <dc:date>2020-02-21T13:13:50Z</dc:date>
    </item>
    <item>
      <title>SolutionIn order to resolve</title>
      <link>https://community.cisco.com/t5/network-security/snort-2-9-5-may-generate-an-error-if-local-rules-are-enabled/m-p/2554263#M925685</link>
      <description>&lt;H4&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/H4&gt;&lt;P&gt;In order to resolve this issue install SEU 915 or higher.&lt;/P&gt;&lt;H4&gt;&lt;BR /&gt;&lt;STRONG&gt;Root Cause&lt;/STRONG&gt;&lt;/H4&gt;&lt;P&gt;An issue has been identified with custom rules or Emerging Threat rules that can violate the Snort rule syntax. These rules can cause the Detection Engine to repeatedly restart. Sourcefire provided rules do not contain these syntax errors and will not cause this problem.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Snort does rule validation upon start up.&amp;nbsp; With Snort 2.9.4, when a rule is determined invalid, then a warning is written to syslog. However, Snort will continue to load omitting that rule.&amp;nbsp; The Snort delivered in SEU 913 generates an error for invalid rules instead of a warning, which prevents Snort from loading.&amp;nbsp; With the release of SEU 915, we simply made Snort 2.9.5 behave the same way Snort 2.9.4 does, which is to display a warning for invalid rules, but continue to load.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Invalid third party rule syntax is still an issue as SEU 915 will not correct them.&amp;nbsp; To make sure rules are valid you can simply open an IPS policy in the editor and save it, or manually apply the policy.&amp;nbsp; You will be notified if there are any invalid rules active in that policy.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 17:26:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort-2-9-5-may-generate-an-error-if-local-rules-are-enabled/m-p/2554263#M925685</guid>
      <dc:creator>Nazmul Rajib</dc:creator>
      <dc:date>2014-07-03T17:26:15Z</dc:date>
    </item>
  </channel>
</rss>

