Additional troubleshooting / possible root cause found for Snort Portscan Detection preprocessor not generating portscan alerts

Subject: Additional troubleshooting / possible root cause found for Snort Portscan Detection preprocessor not generating portscan alerts


Good day from Singapore,


Reporter: Mr. Turritopsis Dohrnii Teo En Ming

Date: 22 Sep 2026 Tuesday 7.15 pm

Country: Singapore


I performed further testing on pfSense CE 2.9.0 with Snort package 4.1.10 / Snort 2.9.20_9.


The sfPortscan preprocessor itself is correctly generated in the WAN snort.conf:


preprocessor sfportscan: \

    scan_type { all } \

    proto { all } \

    memcap { 10000000 } \

    sense_level { high } \

    ignore_scanners { $HOME_NET }


Stream5 is also enabled:


track_tcp yes

track_udp yes


The generated file:


preproc_rules/preprocessor.rules


contains the sfPortscan GID 122 rules, including:


gid: 122; sid: 1   PSNG_TCP_PORTSCAN

gid: 122; sid: 5   PSNG_TCP_FILTERED_PORTSCAN

gid: 122; sid: 21  PSNG_UDP_FILTERED_PORTSCAN


However, the generated snort.conf does not define PREPROC_RULE_PATH, does not include preprocessor.rules, and does not contain config autogenerate_preprocessor_decoder_rules.


The normal rule includes are only:


include $RULE_PATH/snort.rules

include $RULE_PATH/flowbit-required.rules

include $RULE_PATH/custom.rules


I also checked those three included rule files for gid: 122, and none contained any GID 122 rules.


Controlled test


I created a test configuration and added:


var PREPROC_RULE_PATH preproc_rules


and:


include $PREPROC_RULE_PATH/preprocessor.rules


snort -T then successfully validated the configuration:


Snort successfully validated the configuration!

Snort exiting


I then stopped only the WAN Snort process, added the same two lines to the generated WAN snort.conf, and started Snort directly using the same command line normally used by pfSense, 

so that pfSense would not regenerate snort.conf.


/usr/local/bin/snort -R _44907 -M -D --daq pcap --daq-mode passive --treat-drop-as-alert -l /var/log/snort/snort_igc044907 --pid-path /var/run --nolock-pidfile --no-interface-pidfile -G 44907 \

-c /usr/local/etc/snort/snort_44907_igc0/snort.conf -i igc0


After doing this, sfPortscan immediately started generating GID 122 alerts from external scans. Examples:


[122:21:1] (portscan) UDP Filtered Portscan

[122:5:1] (portscan) TCP Filtered Portscan


The same external scanner that previously generated normal Snort Nmap signature alerts but no sfPortscan alerts then generated:


[122:21:1] (portscan) UDP Filtered Portscan


Therefore, my testing suggests that sfPortscan itself is functioning, but its GID 122 rules in preproc_rules/preprocessor.rules are not being loaded by the pfSense-generated Snort configuration.


Another observation is that starting Snort normally from the pfSense GUI regenerates snort.conf and removes the manually added PREPROC_RULE_PATH and include $PREPROC_RULE_PATH/preprocessor.rules lines, 

after which the workaround is lost.


I reproduced the original failure with both Max-Detect and Security IPS policies, so the problem does not appear to be specific to Max-Detect.


Could the Snort package maintainer please check whether preprocessor.rules should be included/processed when generating the interface snort.conf?


Ordinary Snort Nmap signatures were working before the workaround. That proves the failure wasn't caused by traffic failing to reach Snort. For example, I had ET SCAN NMAP OS Detection Probe alerts 

while GID 122 remained completely absent.


My experiment demonstrates that loading preprocessor.rules restores GID 122 alerts; the package maintainer can determine why the generated Snort configuration isn't loading/processing those rules and what the 

correct permanent fix should be.


Thank you very much.


Regards,


Mr. Turritopsis Dohrnii Teo En Ming

Republic of Singapore

22 Sep 2026 Tuesday 7.34 pm Singapore Time






REFERENCES

================


[1] https://lists.freebsd.org/archives/freebsd-amd64/2026-September/000258.html


[2] mail-archive.com - NIL


[3] https://marc.info/?l=freebsd-amd64&m=179007700292132&w=2


[4] https://lists.snort.org/pipermail/snort-users/2026-September/000905.html


[5] mail-archive.com - NIL


[6] https://marc.info/?l=snort-users&m=179009094907176&w=2


[7] https://forum.netgate.com/topic/201425/bug-report-snort-ids-ips-portscan-preprocessor-cannot-detect-any-port-scans-in-pfsense-ce-2.9.0-firewall


[8] https://redmine.pfsense.org/issues/17120


[9] https://lists.snort.org/pipermail/snort-devel/2026-September/000232.html


[10] mail-archive.com - NIL


[1]] https://marc.info/?l=snort-devel&m=179008957105836&w=2


[12] https://seclists.org/snort/2026/q3/28

Comments

Popular posts from this blog

Estimated Total Expenses in Taiwan from 6 Aug 2025 to 12 Aug 2025 (Version 15 Aug 2025)

Teo En Ming’s Book 2 (13 June 2025 Edition) Cloud Storage Download Links

Linux 6.18 Released With Many New Features, Likely This Year's LTS Kernel