Snort Inline drop/reject and pass/alert in rules
- 
 Hi, 
 I have:
 pfsense: 2.6.0
 snort: 4.1.6 (IPS mode: Inline)I'm trying to apply two rules, e.g. (this is just a simple example): pass icmp 192.168.0.10 any -> any any (msg:"CUSTOM ping"; sid:9990007;) 
 drop icmp any any -> any any (msg:"CUSTOM ping"; sid:9990008;)I always have all ip blocked (also 192.168.0.10). I want to block all traffic except selected IP addresses. What rules should I save for this to work properly? Any help is welcome. 
 Regards
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.