mrash / fwsnort

Application Layer IDS/IPS with iptables
http://www.cipherdyne.org/fwsnort/
GNU General Public License v2.0
73 stars 15 forks source link

All rules fail on Debian #19

Open nigelhorne opened 2 years ago

nigelhorne commented 2 years ago

I just ran

apt-get install fwsnort
fwsnort --update-rules
fwsnort

and got this output:

[+] Testing /sbin/iptables for supported capabilities...
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
    Snort Rules File          Success   Fail      Total

[+] emerging-all.rules        0         23074     23074
                              =============================
                              0         23074     23074

[+] No rules parsed.

[+] Logfile: /var/log/fwsnort/fwsnort.log
[-] No Snort rules could be translated, exiting

Looks to me like just about every line, according to fwsnort.log, fails with an unsupported keyword "metadata".