Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SNORT - sfportscan - sense_level

    Scheduled Pinned Locked Moved pfSense Packages
    3 Posts 3 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      podilarius
      last edited by

      Hello,
      I am getting far to many false positives on my WAN interface as I have a very active FW. According to a few sites I have found, you can set sense_level to low for sfportscan. The option does not appear in pfSense. I would love to see a drop down box in the preprocessors screen to set this value.

      Is there another way to set this in the mean time?

      Thank you so much for you work on getting this into pfSense.

      Pod.

      1 Reply Last reply Reply Quote 0
      • D
        darklogic
        last edited by

        Does this happen when you have the portscan preprocessor enabled?

        I posted something on this few days ago when I was having some issues with the SNORT interface preprocessor with the SMTP normalizer causing false positives and I believe someone else posted they had the same thing going on. I am also getting a lot of false postives when the port scan preprocessor is enabled. It got to a point I had to disable the two. I would really like to run them, but it is to much of an issue having legitament IP's getting blocked.

        1 Reply Last reply Reply Quote 0
        • J
          jamesdean
          last edited by

          @podilarius:

          Hello,
          I am getting far to many false positives on my WAN interface as I have a very active FW. According to a few sites I have found, you can set sense_level to low for sfportscan. The option does not appear in pfSense. I would love to see a drop down box in the preprocessors screen to set this value.

          Is there another way to set this in the mean time?

          Thank you so much for you work on getting this into pfSense.

          Pod.

          Added to the todo list.

          James

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.