Q: When I make any Interface settings changes, on the DC, all of the interfaces stop seeing traffic. How do I fix this?
/etc/rc.d/init.d/controlde stopall
/etc/rc.d/init.d/controlde startall
Sourcefire sells IDS appliances based on Snort. The sensors or probes are called Intrusion Sensors and the optional central mgt box is called the Defense Center (DC). I have purchased a few of these and will be tracking some of the issues and oddities here. (Note: I have no relationship with Sourcefire beyond that of satisfied customer.)
Q: When I make any Interface settings changes, on the DC, all of the interfaces stop seeing traffic. How do I fix this?
/etc/rc.d/init.d/controlde stopall
/etc/rc.d/init.d/controlde startall
Q: How do I determine the version numbers of the software I am running?
Q: How do I generate "troubleshoot:" files to send to Sourcefire support?
Update! Here's an easier way: just log in as root, run sf_troubleshoot.pl, then look for the results file in /var/tmp
It's in the "Defense Center User Guide", but the requests for troubleshoot files are so frequent that having the answer here will save time. (Also, the process is arcane!)