Welcome, Guest. Please login or register.
Did you miss your activation email?
Friday 27 May 2022, 04:44:24 pm

Login with username, password and session length

Get the new Updates directly from Endian  HERE
14152 Posts in 4328 Topics by 6305 Members
Latest Member: ekraft-fcc
Search:     Advanced search
Pages: 1 2 3 4 [5] 6 7 8 9 10
 41 
 on: Monday 30 August 2021, 07:01:01 am 
Started by Nclear - Last post by Nclear
Hello,

Im seeing this in the system logs after starting snort, how would you go about resolving this issue? Here is the list of flowbits not checked.

   2021-08-29 13:51:31   snort (12132) +++++++++++++++++++++++++++++++++++++++++++++++++++
System   2021-08-29 13:51:31   snort (12132) Initializing rule chains...
System   2021-08-29 13:51:31   snort (12132) /var/signatures/snort/processed/auto/3coresec.rules(7) threshold (in rule) is deprecated; use detection_filter instead.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.Tesch" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.koobfacecheck" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.HTA.Download" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.applephish" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.DROPIP" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "et.GENOME.AV" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.zipfile" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.IRC.BOT.CntSOCPU" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "http.dottedquadhost.gz" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.Multimedia.Download" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET..in.http" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.Anunanak.HTTP.1" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ETPRO.Microsoft.Excel" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.MP4.Download" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "http.dottedquadhost.docx" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ETPRO.njratgeneric" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.genericphish_Tesco" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.Cryptocurrency_Phish" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.SecondaryFlash.Req" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "http.dottedquadhost.rar" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "ET.TorIP" is set but not ever checked.
System   2021-08-29 13:51:34   snort (12132) flowbits key "http.dottedquadhost.vbs" is set but not ever checked.

 42 
 on: Tuesday 24 August 2021, 01:41:10 am 
Started by rudiratlos63@yahoo.com - Last post by rudiratlos63@yahoo.com
Hi,
I can not setup a 2. connection. If try to add a new connection. the new entry is not showing up under connections.

 43 
 on: Tuesday 24 August 2021, 01:33:56 am 
Started by rudiratlos63@yahoo.com - Last post by rudiratlos63@yahoo.com
Hi,
I have a running tunnel between 2 endian community editions. everything works.
Now I tried to use IKE2 function to use multiple subnets. but the endian gui is not storing the second subnet.

 44 
 on: Tuesday 24 August 2021, 12:52:48 am 
Started by beto2p - Last post by sisaendian
Does Anybody knows the process to manually upgrade Clamav?  Shocked Shocked

 45 
 on: Sunday 15 August 2021, 01:53:23 am 
Started by Nclear - Last post by Nclear
Hello,

I've recently installed the newest version of the EFW community edition, after install when trying to boot I'm prompted with a grub cli declaring that no such device exists. I've installed to an NVM drive, is this possibly a UEFI/Legacy mode issue?

Thanks

 46 
 on: Sunday 18 July 2021, 12:08:39 am 
Started by meazz1 - Last post by meazz1
I am sadden, 590 views and no taker. I really wanted to try this out but could not figure out the proper IOT VLAN setup with firewall rules.

 47 
 on: Friday 09 July 2021, 12:57:47 pm 
Started by jasonwebster - Last post by jasonwebster
Hello, I'm using version 3.2 and cannot access the Web GUI. And I get a notification:

The following error was encountered:

 Connection Failed

The system returned:  (110) Connection timed out

Any help? Thanks!


 48 
 on: Thursday 08 July 2021, 11:41:00 pm 
Started by meazz1 - Last post by meazz1
New to Endian. I have been using ClearOS and Mikrotik.
I'm setting up Endian Community in my x86 PC which has 2 NICs. So, one eth0 is setup for WAN/external and other eth1 is my LAN port. I went thru the default installation and I have a working router with just LAN.

I want to set up a VLAN for my IOT and isolate it from LAN access. Doesn't matter if LAN has access to VLAN or not.

When I tried to create the VLAN I lost access.
Any help with a quick and simple steps to accomplish this is appreciated.

LAN:192.168.4.0/24
VLAN:10.0.20.0/24
Unifi 8-port switch: Tagged and untagged traffic ( it's already setup and working).

 49 
 on: Friday 02 July 2021, 11:22:08 pm 
Started by miki22 - Last post by marco
Sorry, one question:

every time I open an endian firewall it tells me: "register your product for free updates"

I have registered several times with our company email info@ourdomain

We also receive a confirmation email but then it always comes out:

"The email address provided has not yet been registered. Please create a new account"

does it happen to you too? Thanks sorry


Solved:

(from endian site)

For versions 3.2.1 and above:
1 – Enter the email address you used to register in the final step of the setup wizard. If you accidentally skipped this step you can still go to System->Updates in the menu and enter your email address there.
2 – Connect to your firewall via SSH (on Windows you may use putty).
3 – Run efw-upgrade.
There is no GUI implementation in previous versions. Therefore you will need to connect to your firewall via SSH already at the beginning.

Bye

Marco!

 50 
 on: Thursday 01 July 2021, 07:37:54 pm 
Started by Paul.Porlock - Last post by Paul.Porlock
Hi,
I need to update an "old" Endian Firewall Comunity, the version is 2.4.1. I would like to upgrade it to a more recent version (not necessarily the last one). Using SSH, I obtain:

Code:
root@efw-1298305490:~ # efw-upgrade -s
Please choose the appropriate channel for your enviroment and hit [ENTER]
1) Production (stable releases)
2) Development (bleeding edge)
1
Please enter your username and hit [ENTER]:
myusername@mail.com


Loading cache...
Updating cache...               ######################################## [100%]

Fetching information for 'efw-community'...
-> myusername@mail.com:*@updates.endian.org/stable/repodata/repomd.xml
repomd.xml                      ######################################## [ 25%]
error: Failed acquiring release file for 'efw-community':
error: myusername%40mail.com:community@updates.endian.org/stable/repodata/repomd.xml: The requested
URL returned error: 401

Updating cache...               ######################################## [100%]

Channels have no new packages.
ERROR: Error during upgrade
root@efw-1298305490:~ #

Obviously "myusername@mail.com" replace my real email which is already registered for update.

Thank you
P.

Pages: 1 2 3 4 [5] 6 7 8 9 10
Page created in 0.047 seconds with 15 queries.
Powered by SMF 1.1 RC2 | SMF © 2001-2005, Lewis Media Design by 7dana.com