Friday, 4 October 2013

Dovecot Configuration for POP & IMAP with SSL +Sieve (Mail filtering) and IMAP Quota on SENDMAIL

1.       Install the dovecot package on Sendmail server.

[root@mail01 mail]# yum install dovecot*

[root@mail01 mail]# rpm -qa | grep dovecot
dovecot-2.0.9-5.el6.x86_64
dovecot-pigeonhole-2.0.9-5.el6.x86_64

2.       Open /etc/dovecot/dovecot.conf file and change the following parameters.

[root@mail01 mail]# vi /etc/dovecot/dovecot.conf

protocols = imap pop3 lmtp sieve
mail_location = maildir:~/Maildir

# disable_plaintext_auth  value is no if pop3 need to connect on 110 port  otherwise it will connect only on secure PLAIN connection 995 port. Comment out if need to connect on 110 port.


#disable_plaintext_auth = no


Sieve (Mail filtering Language) :

Sieve is a language for filtering e-mail messages. It support as a plug-in for Dovecot's Local Delivery Agent (LDA) and also for its LMTP service. The plug-in implements a Sieve interpreter, which filters incoming messages using a script specified in the Sieve language. The Sieve script is provided by the user through New Webmail UI and, using that Sieve script, the user can customize how incoming messages are handled. Messages can be delivered to specific folders, forwarded, rejected, discarded, etc.


The managesieve daemon will listen on port 2000 but some other version it listen on port 2000. request to kindly change 20-managesieve.conf  file if it is not listen on port 2000

update /etc/dovecot/conf.d/20-managesieve.conf
service managesieve-login {
  inet_listener sieve {
    port = 2000
  }
}

Sieve Interpreter Configuration:

The part of the Sieve interpreter configuration that is relevant for ManageSieve mainly consists of the settings that specify where the user's scripts are stored and where the active script is located. The ManageSieve service primarily uses the following Sieve interpreter settings in the plugin section of the Dovecot configuration(/etc/dovecot/conf.d) update /etc/dovecot/conf.d/90-sieve.conf :

sieve_dir = ~/sieve       

This specifies the path to the directory where the uploaded scripts are stored. Scripts are stored as separate files with extension '.sieve'.

sieve = ~/.dovecot.sieve
This specifies the location of the symbolic link pointing to the active script in the Sieve storage directory. The Sieve interpreter uses this setting to locate the main script file that needs to be executed upon delivery.



Enabling Sieve plugin:

To use Sieve, you will first need to make sure you are using Dovecot LDA or LMTP (this settings is already  has been defined in above 'Protocol Configuration' section)for delivering incoming mail to users' mailboxes. Then, you need to enable the Pigeonhole Sieve plugin in your configuration:


update /etc/dovecot/conf.d/15-lda.conf
protocol lda {
mail_plugins = $mail_plugins sieve
}
update /etc/dovecot/conf.d/20-lmtp.conf
protocol lmtp {
mail_plugins = $mail_plugins sieve
}

restart the dovecot (/etc/init.d/dovecot restart) and check

#telnet centre-imap-server 2000
it should be listen

Dovecot LDA with MTA (Sendmail, Postfix etc.):

The dovecot-lda is a local mail delivery agent which takes mail from an MTA (sendmail, postfix etc.) and delivers it to a user's mailbox, while keeping Dovecot index files up to date.
Main features of the dovecot-lda are:
1. Sieve language support by the Pigeonhole sieve plugin
2. Mailbox indexing during mail delivery, providing faster mailbox access later
3. Quota enforcing by the quota plugin
To configure dovecot lda with Sendmail kindly update below sendmail.cf file.
update the /etc/mail/sendmail.mc file by making following entry.
dnl # FEATURE(local_procmail, `', `procmail -t -Y -a $h -d $u')dnl
FEATURE(`local_procmail', `/usr/libexec/dovecot/dovecot-lda',`/usr/libexec/dovecot/dovecot-lda -d $u')
MODIFY_MAILER_FLAGS(`LOCAL', `-f')
MAILER(procmail)

 Convert the sendmail.mc file sendmail.cf using m4 language. And restart the sendmail daemon.

[root@mail01 certs]# cd /etc/mail
[root@mail01 mail]# m4 sendmail.mc > sendmail.cf
            [root@mail01 mail]# service sendmail restart
            [root@mail01 mail]# chkconfig sendmail on

----------------------------------------------------------------------------------------------------------------------------
sendmail.cf (the mails will deliver through dovecot-lda instead of procmail )

below 3 lines from sendmail.cf will be removed.


Mlocal,         P=/usr/bin/procmail, F=lsDFMAw5:/|@qSPfhn9, S=EnvFromL/HdrFromL, R=EnvToL/HdrToL,
                T=DNS/RFC822/X-Unix,
                A=procmail -t -Y -a $h -d $u

and below 3 lines will be added into sendmail.cf automatically.

Mlocal,                P=/usr/libexec/dovecot/dovecot-lda, F=lsDFMAw5:/|@qSPhn9, S=EnvFromL/HdrFromL, R=EnvToL/HdrToL, T=DNS/RFC822/X-Unix,
             A=/usr/libexec/dovecot/dovecot-lda -d $u

---------------------------------------------------------------------------------------------------------------------------------



Quota:

First you have the quota root backend configuration, this quota backend specifies the method how Dovecot keeps track of the current quota usage. They don't (usually) specify users' quota limits, that's done by returning extra fields from userdb.
To define quota backend:
update /etc/dovecot/conf.d/90-quota.conf file
plugin {

 quota = maildir:User quota

 }


There are different quota backends that Dovecot can use, but in this document we are defining maildir backend here in this document we   configure maildir backend:
·maildir: Store quota usage in Maildir++ maildirsize files. This is the most commonly used quota for virtual users.

Enabling quota plugins:

update /etc/dovecot/conf.d/10-mail.conf
mail_plugins = $mail_plugins quota

update /etc/dovecot/conf.d/20-imap.conf
mail_plugins = $mail_plugins imap_quota

It will reporting quota information via IMAP.

Per-user quota:
To configure per user basis quota, we need to maintain flat file (/etc/dovecot/users) in dovecot database
Note: After creating user's home directory at your mail server you need to add user information in  /etc/dovecot/users file.

(the users entries should be below like
username:x:uid:gid:Full Name:HOME DIR:BASH:userdb_quota_rule=*:storage=2G

example
jitendrakumar:x:4321:4321:Jitendra Kumar:/home/jitendrakumar:/bin/bash:userdb_quota_rule=*:storage=2G)

now define /etc/dovecot/users into configuration file

update /etc/dovecot/conf.d/auth-system.conf.ext
passdb {
  driver = pam
}

userdb {
   driver = passwd-file
  args = username_format=%u /etc/dovecot/users
}


Quota warnings:


Now configure Dovecot to run an external command when user's quota exceeds a specified limit. Note that the warning is ONLY executed at the exact time when the limit is being crossed.
update /opt/dovecot/etc/dovecot/conf.d/90-quota.conf

plugin {
 

  quota_warning = storage=75%% quota-warning 75 %u

  quota_warning2 = storage=90%% quota-warning 90 %u

}



service quota-warning {

 executable = script /usr/local/bin/quota-warning.sh

 unix_listener quota-warning {

  mode = 0666

    }

}


With the above example when user's quota exceeds 75%, quota-warning.sh is executed with parameter 75. The same goes for when quota exceeds 90%.
You have to create the quota-warning.sh
touch /usr/local/bin/quota-warning.sh
chmod 700 /usr/local/bin/quota-warning.sh
chmod +x  /usr/local/bin/quota-warning.sh

Here is an example that sends a mail to the user:
vim /usr/local/bin/quota-warning.sh

#!/bin/sh
PERCENT=$1
USER=$2
cat << EOF | /usr/libexec/dovecot/deliver -d $USER -o "plugin/quota=maildir:User quota"

From: mailadmin-centre@example.com
Subject: Mailbox Quota Warning: $PERCENT% Full.
Mailbox quota report:
    * Your mailbox is now $PERCENT% full, please clear some files for
      further mails.
EOF




Over Quota:
If user is over quota, you can configure following settings in /etc/dovecot/conf.d/15-lda.conf

quota_full_tempfail = yes (after exceeding quota,  mails will deliver to queue directory instead of bounce back, after deleting mails from users or increasing quota by mailadmin the mails will deliver  to user INBOX automatically)

quota_full_tempfail = no (after exceeding quota mails will be bounce back)

Step by Step SENDMAIL + SMTP AUTH & "Maildir format for Mailbox" Configuration

Sendmail is most popular MTA for mail services. It is an open source which comes with Linux OS.
I am configuring Sendmail on CentOS 6.3 64 bit machine. I have already configured yum on CentOS which I am not covering in this document.

1.       Check, whether server is 64 bit machine or not.

[root@mail01 ~]# getconf LONG_BIT
64

2.       Checking the OS version and Linux kernel used for installation.

[root@mail01 ~]# cat /etc/redhat-release
CentOS release 6.3 (Final)

[root@mail01 ~]# uname -a
Linux mail01.example.com 2.6.32-279.el6.x86_64 #1 SMP Fri Jun 22 12:19:21 UTC 2012 x86_64 x86_64 x86_64 GNU/Linux

3.       Install Sendmail on server using yum and checking the installed Sendmail version.

[root@mail01 ~]# yum install sendmail*

[root@mail01 ~]# rpm -qa | grep sendmail                          
sendmail-cf-8.14.4-8.el6.noarch
sendmail-8.14.4-8.el6.x86_64

4.       I will use M4 language to convert the configuration file from sendmail.mc to sednmail.cf. So install m4 package and check the installed version.

[root@mail01 ~]# yum install sendmail*

[root@mail01 ~]# rpm -qa | grep m4
m4-1.4.13-5.el6.x86_64

5.       The mail configuration files of Sendmail store in /etc/mail directory. The mail configuration file is sendmail.mc which could be edited as per our requirement on mailing server.
 

Comment the following line so that other system can use this mail server. Otherwise mail will work only on localhost.

From:
DAEMON_OPTIONS(`Port=smtp,Addr=127.0.0.1, Name=MTA')dnl

 To:
dnl # DAEMON_OPTIONS(`Port=smtp,Addr=127.0.0.1, Name=MTA')dnl

6.       Allow the SMTP authentication with secure connection. Uncomment the following lines.

define(`confAUTH_OPTIONS', `A ')dnl

TRUST_AUTH_MECH(`EXTERNAL DIGEST-MD5 CRAM-MD5 LOGIN PLAIN ')dnl
define(`confAUTH_MECHANISMS', `EXTERNAL DiIGEST-MD5 CRAM-MD5 LOGIN PLAIN ')dnl

define(`confCACERT_PATH', `/etc/pki/tls/certs')dnl
define(`confCACERT', `/etc/pki/tls/certs/ca-bundle.crt')dnl
define(`confSERVER_CERT', `/etc/pki/tls/certs/sendmail.pem')dnl
define(`confSERVER_KEY', `/etc/pki/tls/certs/sendmail.pem')dnl
define(`confCLIENT_CERT', `/etc/pki/tls/certs/sendmail.pem')dnl
define(`confCLIENT_KEY', `/etc/pki/tls/certs/sendmail.pem')dnl

LOCAL_DOMAIN(`example.com')dnl

I used example.com domain for my mail setup. Here you can provide your domain of mails.

7.       I will create a SSL certificate so that STARTTLS will function. Run the following commands to create a Certificate Authority (CA).

[root@mail01 mail]# mkdir  /etc/pki/tls/certs
[root@mail01 mail]#cd  /etc/pki/tls/certs

[root@mail01 certs]#  openssl req -new -x509 -keyout cakey.pem -out ca-bundle.crt -days 1865
[root@mail01 certs]# openssl req –nodes –new  -x509 -keyout  sendmail.pem –out sendmail.pem –days  1865

[root@mail01 certs]# chmod 600 sendmail.pem

We can verify the content of Certificate.

[root@mail01 certs]# openssl x509 –noout –text –in sendmail.pem

8.       Now start up the saslauth daemon and run the following.

[root@mail01 certs]# /etc/init.d/saslauthd start
[root@mail01 certs]# chkconfig saslauthd on

This command tells SASLv2 to look at the /etc/shadow file for authentication. There are other ways to authenticate but are beyond the scope of this howto. I’ve also read that the saslauth daemon does not support CRAM-MD5 or DIGEST-MD5.

9.       Convert the sendmail.mc file sendmail.cf using m4 language. And restart the Sendmail daemon.

[root@mail01 certs]# cd /etc/mail
[root@mail01 mail]# m4 sendmail.mc > sendmail.cf

[root@mail01 mail]# service sendmail restart
[root@mail01 mail]# chkconfig sendmail on

10.To accept the entry of local hostname Make entry into /etc/mail/local-host-name. Place any domains or hosts that Sendmail will receive mail for. For example, to configure a mail server to accept mail for the domain example.com and the host mail.example.com, add these entries to local-host-names

example.com
mail.example.com

11.   Make entry of your domain into /etc/mail/access file and update database.

Connect:example.com               RELAY
Connect:localhost                       RELAY
Connect:127.0.0.1                       RELAY

12.   Update the access file database.

[root@mail01 mail]# makemap hash access.db < access

13.   By default Sendmail uses Mailbox format into mbox format which performs slower. So for better performance I will use Maildir format. For changing this configuration create a file /etc/procmailrc and add the following entries.
 
[root@mail01 mail]# vi /etc/procmailrc

ORGMAIL=$HOME/Maildir/
DEFAULT=$HOME/Maildir/

14.   Restart the sendmail service on server.


[root@mail01 mail]# service sendmail restart

Monday, 23 September 2013

Step by Step Installation & Configuration of LDAP+SAMBA on CentOS 5


I am defining here installation and configuration of LDAP server and integrate with SAMBA services. If you will work windows at client side, Samba integration is necessary with LDAP otherwise NT Password will not be accepted by LDAP server. Here we will go step by step to configure LDAP and samba server.

I am using Cent OS 5.5 64 bit Operating system with kernel 2.6.18-194.el5.


I will use LDAP domain example.com for installation procedure.

1.       My system IP address is 10.226.2.66 and hostname is ldapnoida.example.com. If you are not using name server, add hostname entry into /etc/hosts file.

# vim /etc/hosts

10.226.2.66     ldapnoida.example.com ldapnoida


2.  I will install all packages from yum repository so please configure yum before installation the packages on server. I am not covering yum in this document. Here I will install openldap on server.

# yum install *openldap*

This command will install following LDAP packages on your system.
 
nss_ldap.i386          
nss_ldap.x86_64        
openldap.i386          
openldap.x86_64        
openldap-clients.x86_64
openldap-servers.x86_64
Available Packages
nss_ldap.i386          
nss_ldap.x86_64        

3.  Create LDAP password using slappasswd command. It gave here password root123 and generate cypted password as per below screenshot.I will paste this encrypted password in /etc/openldap/slapd.conf file.


4 .       Open file /etc/openldap/slapd.conf and update the following fields on ldap server.
database        bdb
suffix          "dc=example,dc=com"
rootdn          "cn=Manager,dc=example,dc=com"
rootpw      {SSHA}+VQndTOziGTtICTQXuY8ExicsLjVlVxd
 5. Open file /etc/openldap/ldap.conf and update the following fields on ldap server.
 BASE dc=example,dc=com
URI  ldap://ldapnoida.example.com/
6. Open file /etc/ldap.conf and add the following lines into this.
base dc=example,dc=com
URI ldap://ldapnoida.example.com/
And comment the line
#host 127.0.0.1
7.   Restart the LDAP service on server.
# /etc/init.d/ldap restart
8.     Copy the DB_CONFIG.example file for slapd DBS/HDB database into LDAP configuration file.
cp /etc/openldap/DB_CONFIG.example /var/lib/ldap/DB_CONFIG
9.     Restart the Ldap service and make ldap service on system boot.
# service ldap restart
# chkconfig ldap on
 10.    Update migrate_common.ph file for LDAP directory structure creation.
[root@ldapnoida ~]# cd /usr/share/openldap/migration/
[root@ldapnoida migration]# vim migrate_common.ph
$DEFAULT_MAIL_DOMAIN ="example.com";
$DEFAULT_BASE ="dc=example,dc=com";
11.      LDAP imports the directory structure into LDIF format so we are creating base structure LDIF file to import into LDAP directory.
[root@ldapnoida migration]#./migrate_base.pl > base.ldif
[root@ldapnoida migration]#ldapadd -x -D "cn=Manager,dc=example,dc=com" -W -f  base.ldif
It will ask LDAP password. Type ldap password as defined above “root123” and it will generate basic LDAP directory structure.
12.     Create a system user so that we can export system user into LDAP server.
root@ldapnoida  migration]# useradd jitendrakumar
root@ldapnoida migration ]#  passwd jitendrakumar
13.Migrate system account having uid above 500 into LDPP server.
[root@ldapnoida migration]# grep "x:[5-9][0-9][0-9]" /etc/passwd >passwd
[root@ldapnoida migration]# grep "x:[5-9][0-9][0-9]" /etc/group > group
[root@ldapnoida migration]#./migrate_passwd.pl passwd > passwd.ldif
[root@ldapnoida migration]#./migrate_group.pl group > group.ldif
[root@ldapnoida migration]# ldapadd -x -D "cn=Manager,dc=example,dc=com" -W -f passwd.ldif
[root@ldapnoida migration]# ldapadd -x -D "cn=Manager,dc=example,dc=com" -W -f group.ldif
14.  Installing SAMBA packages on server.
[root@ldapnoida migration]# yum install *samba*
15.   Copy the Samba schema into LDAP schema repository.
cp /usr/share/doc/samba-3.0.33/LDAP/samba.schema /etc/openldap/schema/
16.  Edit the file /etc/openldap/slapd.conf and include samba.schema location into ldap configuration file.
[root@ldapnoida migration]# vim /etc/openldap/slapd.conf
include         /etc/openldap/schema/samba.schema
17.     Restart the LDAP Service on server.
[root@ldapnoida migration]# service ldap restart
Stopping slapd:                                            [  OK  ]
Starting slapd:                                            [  OK  ]
[root@ldapnoida migration]#
18.     Download EPEL RPM package and install it on server.
[root@ldapnoida migration]# wget http://dl.fedoraproject.org/pub/epel/5/x86_64/epel-release-5-4.noarch.rpm
--2013-09-20 14:58:00--  http://dl.fedoraproject.org/pub/epel/5/x86_64/epel-release-5-4.noarch.rpm
Resolving dl.fedoraproject.org...209.132.181.27, 209.132.181.23, 209.132.181.24, ...
Connecting to dl.fedoraproject.org|209.132.181.27|:80...connected.
HTTP request sent, awaiting response... 200 OK
Length: 12232 (12K) [application/x-rpm]
Saving to: `epel-release-5-4.noarch.rpm'
100%[==============================================================================================================>] 12,232      --.-K/s   in 0.02s
2013-09-20 14:58:01 (739 KB/s) - `epel-release-5-4.noarch.rpm' saved [12232/12232]
[root@ldapnoida migration]  rpm –Uvh epel-release-5-4.noarch.rpm
19.     Install smbldap-tools and phpldapadmin on server.
[root@ldapnoida migration]# yum –y install smbldap-tools
[root@ldapnoida migration]# yum –enablerepo=epel –y install phpldapadmin
20.     Configure Phpldapadmin on server to manage LDAP DIT through graphically.
[root@ldapnoida ~]# vi /etc/httpd/conf.d/phpldapadmin.conf
Alias /phpldapadmin /usr/share/phpldapadmin/htdocs
Alias /ldapadmin/usr/share/phpldapadmin/htdocs
<Directory /usr/share/phpldapadmin/htdocs>
Order Deny,Allow 
Deny from all 
Allow from 127.0.0.1 10.226.0.0/16 # IP address you allow
</Directory>
[root@ldapnoida ~]#/etc/rc.d/init.d/httpd restart
To access phpldapadmin use URL “http://(yourhostname or IP address)/ldapadmin “
21. To access phpldapadmin console user following credentials.
User Name: cn=Manager,dc=example,dc=com
Password: root123
Password is LDAP rootdn password as defined above in document.
22.     Take the backup of smb.conf and create a new
smb.conf file from ldap enabled configuration file on ldap server.
mv /etc/samba/smb.conf  /etc/samba/smb.conf.backup
cp /usr/share/doc/smbldap-tools-0.9.6/smb.conf /etc/samba/smb.conf
23.    Change the /etc/samba/smb.conf configuration file for LDAP.
[root@ldapnoida migration]# vim /etc/samba/smb.conf
       workgroup = example
  netbios name = ldap
      unix password sync = yes
      ldap passwd sync = yes
       passwd program = /usr/sbin/smbldap-passwd -u "%u"
       passwd chat = "Changing *\nNew password*" %n\n "*Retype new password*" %n\n"
        Dos charset = CP932
      Unix charset = UTF-8
 passdb backend = ldapsam:ldap://10.226.2.66/
        ldap admin dn = cn=Manager,dc=example,dc=com
       ldap suffix = dc=example,dc=com
       ldap group suffix = ou=Group
       ldap user suffix = ou=People
       admin users = admin
24.    Create following directory and set their permissions.
[root@ldapnoida  ~]#mkdir /home/netlogon
[root@ldapnoida  ~]# mkdir /home/profiles
[root@ldapnoida  ~]# chmod 777 /home/profiles.
25.      Restarted samba service and make it permanent.
[root@ldapnoida  ~]# service smb restart
[root@ldapnoida  ~]# chkconfig smb on
26.    Set the SAMBA Password.
[root@ldapnoida  ~]# smbpasswd –W
27.      Change to following directory and set the permission of configure.pl script.
[root@ldapnoida migration]# cd /usr/share/doc/smbldap-tools-0.9.6/
[root@ldapnoida smbldap-tools-0.9.6]# chmod 755 configure.pl
[root@ldapnoida smbldap-tools-0.9.6]#./configure.pl
You can check SID with “net getlocalsid” command. If it is same press enter.
Enter domain name to append to mail address [ ] > example.com


28.     Open file /usr/share/doc/smbldap-tools-0.9.6/smbldap.conf and change the required parameters into this file.
[root@ldapnoida smbldap-tools-0.9.6]# pwd
/usr/share/doc/smbldap-tools-0.9.6
[root@ldapnoida smbldap-tools-0.9.6]# net getlocalsid
[2013/09/20 15:50:03, 0] param/loadparm.c:map_parameter(2794)
Unknown parameter encountered: "min passwd length"
[2013/09/20 15:50:03, 0] param/loadparm.c:lp_do_parameter(3541)
Ignoring unknown parameter "min passwd length"
SID for domain LDAP is: S-1-5-21-3088606343-1201082996-3680957859
[root@ldapnoida smbldap-tools-0.9.6]# vi smbldap.conf
SID="S-1-5-21-3088606343-1201082996-3680957859"
slaveLDAP="ldapnoida.example.com"
masterLDAP="ldapnoida.example.com"
suffix="dc=example,dc=com"
sambaUnixIdPooldn="sambaDomainName=$example,${suffix}"
userSmbHome="\\ldap\%U"
userProfile=\\ldap\profiles\%U
mailDomain="example.com"
29.     Open file /usr/share/doc/smbldap-tools-0.9.6/smbldap.conf and change the required parameters into this file.
[root@ldapnoida smbldap-tools-0.9.6]# vim smbldap_bind.conf
# $Id: smbldap_bind.conf 35 2011-02-23 09:07:36Z fumiyas $
#
############################
# Credential Configuration #
############################
# Notes: you can specify two differents configuration if you use a
# master ldap for writing access and a slave ldap server for reading access
# By default, we will use the same DN (so it will work for standard Samba
# release)
slaveDN="cn=Manager,dc=example,dc=com"
slavePw="root123"
masterDN="cn=Manager,dc=example,dc=com"
masterPw="root123"
30.     Restart the samba service and populate the LDAP DIT  on server.
[root@ldapnoida smbldap-tools-0.9.6]# service smb restart
[root@ldapnoida smbldap-tools-0.9.6]#  smbldap-populate
31.     Now I will create admin account and group for domain administrative account.
root@ldapnoida smbldap-tools-0.9.6]#  smbldap-groupadd –a admin
root@ldapnoida smbldap-tools-0.9.6]#  smbldap-useradd –am –g admin admin
32.      We can reset password of admin user with following command.

root@ldapnoida smbldap-tools-0.9.6]#  smbldap-passwd admin

Monday, 5 August 2013

vmap allocation for size 9146368 failed: use vmalloc= to increase size.


We found following error logs in /var/log/message logfile.

Aug  5 14:30:10 snort kernel: vmap allocation for size 9146368 failed: use vmalloc=<size> to increase size.
Aug  5 14:30:10 snort kernel: vmap allocation for size 9146368 failed: use vmalloc=<size> to increase size.
Aug  5 14:30:10 snort kernel: vmap allocation for size 9146368 failed: use vmalloc=<size> to increase size.
Aug  5 14:30:10 snort kernel: vmap allocation for size 9146368 failed: use vmalloc=<size> to increase size.
Aug  5 14:30:10 snort kernel: vmap allocation for size 9146368 failed: use vmalloc=<size> to increase size.

When we checked vmalloc limit was set to 124 MB. Due to low kernel allocated memory, error was coming.

[root@snort ~]# cat /proc/meminfo | grep -i vmalloc
VmallocTotal:     124144 kB
VmallocUsed:         5536 kB
VmallocChunk:       1156 kB

Solution:

Add vmalloc=256M in /boot/grub/grub.conf file to increase the limit of vmalloc kernel parameter.

[root@snort ~]# cat /boot/grub/grub.conf
# grub.conf generated by anaconda
#
# Note that you do not have to rerun grub after making changes to this file
# NOTICE:  You have a /boot partition.  This means that
#          all kernel and initrd paths are relative to /boot/, eg.
#          root (hd0,0)
#          kernel /vmlinuz-version ro root=/dev/mapper/vg_snort-lv_root
#          initrd /initrd-[generic-]version.img
#boot=/dev/sda
default=0
timeout=5
splashimage=(hd0,0)/grub/splash.xpm.gz
hiddenmenu
title CentOS (2.6.32-358.14.1.el6.i686)
        root (hd0,0)
        kernel /vmlinuz-2.6.32-358.14.1.el6.i686 ro root=/dev/mapper/vg_snort-lv_root rd_NO_LUKS LANG=en_US.UTF-8 rd_LVM_LV=vg_snort/lv_root rd_NO_MD SYSFONT=latarcyrheb-sun16  KEYBOARDTYPE=pc KEYTABLE=us rd_LVM_LV=vg_snort/lv_swap rd_NO_DM rhgb quiet crashkernel=auto vmalloc=256M
        initrd /initramfs-2.6.32-358.14.1.el6.i686.img
title CentOS (2.6.32-279.el6.i686)
        root (hd0,0)
#       vmalloc=256MB
        kernel /vmlinuz-2.6.32-279.el6.i686 ro root=/dev/mapper/vg_snort-lv_root rd_NO_LUKS LANG=en_US.UTF-8 rd_LVM_LV=vg_snort/lv_root rd_NO_MD SYSFONT=latarcyrheb-sun16  KEYBOARDTYPE=pc KEYTABLE=us rd_LVM_LV=vg_snort/lv_swap rd_NO_DM rhgb quiet vmalloc=256M
        initrd /initramfs-2.6.32-279.el6.i686.img


Reboot the system and vmalloc size is increased upto 256MB.

[root@snort ~]# cat /proc/meminfo | grep -i vmall
VmallocTotal:     262144 kB
VmallocUsed:      115536 kB
VmallocChunk:      41156 kB