Re: Compiling so_rules for FreeBSD 13
Noah Dietrich <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CA+N0JEy8xP2q7vNEuTqxgGcwydqAw3OQaSuedKG3CQ6RcORcbw@mail.gmail.com> |
Assuming your machines are the same architecture, I can't think of any reasons you can't compile the .so rules on one machine and copy them to another one, assuming you're copying all the required files (stub rules mostly). If the architectures or available libraries are different, you could have issues. Noah On Tue, Dec 28, 2021 at 9:14 AM Carlos Lopez <[email protected]> wrote: > Perfect. Many thanks Noah. Only one question: I am using a different > FreeBSD server than the one running snort to manage the rules, do I have to > take into consideration anything to compile the so_rules and pass them? > > > On 28 Dec 2021, at 08:57, Noah Dietrich <[email protected]> wrote: > > I'm working on this feature in PP3 now, it should be available soon. > > Noah > > > On Tue, Dec 28, 2021 at 8:53 AM Carlos Lopez via Snort-users < > [email protected]> wrote: > >> Hi all, >> >> I have installed snort 3.1.19.0 under a FreeBSD 13 host and all it is >> working. Actually, I am using text (registered) rules only, but I would >> like to use Talos_LightSPD rules. For rule management I am using >> pulledpork3. >> >> What would be the proper procedure to compile the so_rules and have >> pulledpork3 generate all the associated files? >> >> Regards. >> _______________________________________________ >> Snort-users mailing list >> [email protected] >> Go to this URL to change user options or unsubscribe: >> https://lists.snort.org/mailman/listinfo/snort-users >> >> To unsubscribe, send an email to: >> [email protected] >> >> Please visit http://blog.snort.org to stay current on all the latest >> Snort news! >> >> Please follow these rules: >> https://snort.org/faq/what-is-the-mailing-list-etiquette >> > > _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette