Guest

Preview Tool

Cisco Bug: CSCvu70529 - Binary rules (SO rules) are not loaded when snort reloads

Last Modified

Oct 13, 2020

Products (35)

  • Cisco Firepower Management Center Virtual Appliance
  • Cisco Firepower Management Center 2500
  • Cisco Firepower Management Center 4600
  • Cisco FirePOWER Appliance 7050
  • Cisco FirePOWER Appliance 8260
  • Cisco FirePOWER Appliance 8360
  • Cisco FirePOWER Appliance 8120
  • Cisco FirePOWER Appliance 8140
  • Cisco AMP 8150
  • Cisco FirePOWER Appliance 8350
View all products in Bug Search Tool Login Required

Known Affected Releases

6.4.0 6.5.0 6.6.0

Description (partial)

Symptom:
When snort reloads you can see the following warning.

Loading all dynamic detection libs from /var/sf/detection_engines/8bc5adb4-aa1a-11ea-92f8-44733de4c989/so_rules/...
WARNING: No dynamic libraries found in directory /var/sf/detection_engines/8bc5adb4-aa1a-11ea-92f8-44733de4c989/so_rules/.
Finished Loading all dynamic detection libs

If the customer is using several intrusion policies, that use the binary rules, then additional warnings like the following could also be seen.

 >  Encoded Rule Plugin SID: 36215, GID: 3 not registered properly. Disabling this rule.?

Conditions:
The issue is there in any Elektra OnBox platform running 6.4+.
Any client who does an SRU update on 6.4 will/can run into this problem
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.