Bill,
Thanks v much for the detailed reply, which gives much more info. Can
visualise the little boxes and data flow. With snort being an optional package,
I guess the only way it can work is to use some sort of hooks in the packet
filter for snort inputs and outputs. Thinking streams, but maybe wrong.
My confusion was the snort block list report, which sort of suggested that
block info was snort generated only.
Pfsense is a really great piece of work and it would be good to contribute to
the effort at some stage. In particular, getting pfsense running on old Sun
hardware. There's a lot of it about, it's cheap, good and it's not X86, which
gives added security. Have never worked with or programmed FreeBSD and almost
nil experience of interpreted languages, but that could be fixed. Have plenty
of old Sun hardware to contribute if anyone is interested in starting a project
and can provide support on hardware related issues..
I guess the first thing to do is to try a FreeBSD install. Debian runs fine
and installed just about out of the box on a V240 class machine, but no idea
how good or stable is the support for FreeBSD on Sparc…
Chris