After update to version 9.719 IPS not working properly anymore. Every 10 minutes snort not running - restarted messages.
This thread was automatically locked due to age.
Hello Community,
The following KB has been released.
https://support.sophos.com/support/s/article/KB-000045966?language=en_US
Regards,
emmosophos What is the underlying cause of this issue?
What does setting ` snortsettings disable_normalization` to 1 (or true?) actually do in layman's terms?
What change in 9.719 caused this issue to begin with?
Details please. Thank you
In 9.719 we enabled normalization for improved IPS detection. However it looks like with some specific traffic, normalization causes snort to crash. We have disabled normalization with the update for now (restoring 9.718 and prior behaviour), while we investigate these crashes.
In 9.719 we enabled normalization for improved IPS detection. However it looks like with some specific traffic, normalization causes snort to crash. We have disabled normalization with the update for now (restoring 9.718 and prior behaviour), while we investigate these crashes.