Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port mirroring?

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 3 Posters 6.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      amrogers3
      last edited by

      Hello, I would like to implement port mirroring on the pfsense firewall to route traffic through a SNORT box for traffic analysis.

      I read some old post about hacking "filter.inc". I don't have a lot of experience with BSD or linux for that matter but I want to learn.

      Can anyone point in the direction of a good book or web post on the matter? Or maybe there is a better way to implement this using a SNORT box?

      Any help is appreciated. Thanks in advance.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        You can do this on 2.0. When you setup a bridge, click the advanced options button and choose the snort interface as the "span port".

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • A
          amrogers3
          last edited by

          @jimp:

          You can do this on 2.0. When you setup a bridge, click the advanced options button and choose the snort interface as the "span port".

          Thank you  :)

          OK, I will have to do some research on bridging. Since the pfSense firewall will be doing a lot of processing due to mirroring all the traffic, is there a recommended minimum hardware requirement needed?

          1 Reply Last reply Reply Quote 0
          • A
            amrogers3
            last edited by

            Also, would it be better to mirror traffic from a switch rather than the pfSense box?

            1 Reply Last reply Reply Quote 0
            • A
              amrogers3
              last edited by

              @amrogers3:

              Also, would it be better to mirror traffic from a switch rather than the pfSense box?

              bumpity bump.

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                I'm not sure I understand the question. Do you mean would it be better to use the switch for port mirroring?
                If so then yes, if your switch supports it, as it won't load your pfSense box.

                Steve

                1 Reply Last reply Reply Quote 0
                • A
                  amrogers3
                  last edited by

                  @stephenw10:

                  I'm not sure I understand the question. Do you mean would it be better to use the switch for port mirroring?
                  If so then yes, if your switch supports it, as it won't load your pfSense box.

                  Steve

                  Hi Steve, yes that was my question. I will use a switch then.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.