• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Snort and Mac OS X users

Scheduled Pinned Locked Moved pfSense Packages
6 Posts 3 Posters 2.7k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    sollostech
    last edited by Jan 16, 2010, 5:30 PM

    I enabled Snort on embedded pfSense 1.2.3 and found the Mac users (including myself) were invariably being blocked. Tried to suppress the alerts associated with the legitimate Mac traffic, but this never worked.

    1 Reply Last reply Reply Quote 0
    • R
      Roodawakening
      last edited by Jan 17, 2010, 4:17 AM

      I've been running my Mac behind pfSense (with Snort, Squid, Squidguard, Denyhosts, Fit123, and HAVP) for months. I suspect it has nothing to do with your Mac, other than perhaps a setting being off. How is Snort configured?

      "The descent to hell is easy. The gates stand open day and night. But to reclimb the slope and escape to the upper air: This is labor."
      –Virgil, Aeneid, Book 6

      Rob

      1 Reply Last reply Reply Quote 0
      • S
        sollostech
        last edited by Jan 17, 2010, 4:45 AM

        I just had the standard config, didn't change anything. I had a few rules enabled and then turned them all of to see if that would help.

        1 Reply Last reply Reply Quote 0
        • R
          Roodawakening
          last edited by Jan 19, 2010, 6:55 AM

          @sollostech:

          I just had the standard config, didn't change anything. I had a few rules enabled and then turned them all of to see if that would help.

          Again…I doubt it has anything to do with the operating system. You might want to check firewall settings on the local (LAN) machines to make sure you don't have a conflict.

          "The descent to hell is easy. The gates stand open day and night. But to reclimb the slope and escape to the upper air: This is labor."
          –Virgil, Aeneid, Book 6

          Rob

          1 Reply Last reply Reply Quote 0
          • S
            sollostech
            last edited by Jan 20, 2010, 3:13 PM

            Don't have any firewall on the machines themselves. I assumed it was a Mac issue only because reading in the forums on my issue I found other posts that had identified the issue with Mac visitors. I will try it again, but set Snort to not block the visitor and just give me the alert error so I can work on figuring this out. Not sure why the exceptions I tried to put it didn't do anything, I guess I did something incorrect.

            1 Reply Last reply Reply Quote 0
            • J
              jamesdean
              last edited by Jan 20, 2010, 10:10 PM

              Use the threshold.conf to suppress the alerts you get.
              Search the forums on how to do that.

              James

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received