Snort Alert for IP on blocklist
Quick question - will a Snort Alert be generated for a bruteforce attempt from an IP that is already included on the pfblockerNG block list?
That seems to be happening for me, and I thought that pfblocker processing happened before Snort.
Thanks in advance.
@efriedman If you have Snort/Suricata on WAN, it sees the packets before the firewall, so will scan all packets that will be dropped anyway. On LAN Snort is after the firewall, as the packet travels to LAN. IOW, it is always "outside" the firewall. So, one should generally run it on LAN.
@efriedman Snort would see things before pfBlockerNG, I believe...
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.