Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort rules order

    Scheduled Pinned Locked Moved IDS/IPS
    34 Posts 2 Posters 3.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Antibiotic @bmeeks
      last edited by

      @bmeeks But snort is more integrated in pfsense than suricata? any profit or doesnt matter ,except multitreading

      bmeeksB 1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks @Antibiotic
        last edited by

        @Antibiotic said in Snort rules order:

        @bmeeks But snort is more integrated in pfsense than suricata? any profit or doesnt matter ,except multitreading

        I do not understand your question. What do you mean by "more integrated" and "any profit"?

        The translation to English does not appear to be working well.

        A 1 Reply Last reply Reply Quote 0
        • A
          Antibiotic @bmeeks
          last edited by Antibiotic

          @bmeeks I mean, suricata also well tested as snort before put to pfsense repo?You are doing snort. who is making suricata for pfsense?

          bmeeksB 1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks @Antibiotic
            last edited by

            @Antibiotic said in Snort rules order:

            @bmeeks I mean, suricata also well tested as snort before put to pfsense repo?

            I created the Suricata package on pfSense, and I have maintained the Snort package for more than 10 years. There is no difference in testing for either package. In fact, the GUI portions of both packages are in many cases identical since they share the same PHP code base.

            Both rely on custom plugins used for blocking on pfSense, and both have underlying binary components provided by an upstream source.

            I still don't really understand your question.

            A 3 Replies Last reply Reply Quote 1
            • A
              Antibiotic @bmeeks
              last edited by

              @bmeeks Ah ok)) clear now

              1 Reply Last reply Reply Quote 0
              • A
                Antibiotic @bmeeks
                last edited by Antibiotic

                @bmeeks Emerging Threats Pro rules is too expensive)))

                1 Reply Last reply Reply Quote 0
                • A
                  Antibiotic @bmeeks
                  last edited by

                  @bmeeks But snort have ja3 fingerprint detection and droping functionality or ja4

                  1 Reply Last reply Reply Quote 0
                  • A
                    Antibiotic @bmeeks
                    last edited by Antibiotic

                    @bmeeks Hello again!
                    Now did dropsid for some rules and its working. But how to make drop action for whole category?Lets say category: emergening-ja3-rules want to drop action for all category.

                    The numbers are going not but orders and click whole category too long or make dropsid with a different numbers. Is it possible to make drop action for whole category? Suricata

                    bmeeksB 1 Reply Last reply Reply Quote 0
                    • bmeeksB
                      bmeeks @Antibiotic
                      last edited by

                      @Antibiotic said in Snort rules order:

                      @bmeeks Hello again!
                      Now did dropsid for some rules and its working. But how to make drop action for whole category?Lets say category: emergening-ja3-rules want to drop action for all category.

                      The numbers are going not but orders and click whole category too long or make dropsid with a different numbers. Is it possible to make drop action for whole category? Suricata

                      Go read this Sticky Post at the top of this sub-forum: https://forum.netgate.com/topic/128480/how-automatic-sid-management-and-user-rule-overrides-work-in-snort-and-suricata.

                      A 1 Reply Last reply Reply Quote 0
                      • A
                        Antibiotic @bmeeks
                        last edited by

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.