Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SNORT and transparent firewall

    pfSense Packages
    2
    6
    3.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hypemedia
      last edited by

      Hi
      I have a Pfsense box setup as firewall in transparent mode (bridged). I have also a SNORT package configured on the WAN zone (there is a bridge between WAN and DMZ).

      In the system log I get no error message regarding SNORT all is looking normal, the problem is that I don't get any alerts on the SNORT interface and this is impossible is like the system is not working.

      Any advice on how I can debug this problem?

      Thanks

      1 Reply Last reply Reply Quote 0
      • ?
        A Former User
        last edited by

        As far as I can remember snort does not run in a bridge unless you manually set up the home net and external net. Try going into the snort interface settings (Services>snort>e button to your right) scroll down and click view list next to home net. Post the output of that. Change IPs to protect the innocent.

        1 Reply Last reply Reply Quote 0
        • H
          hypemedia
          last edited by

          Hi
          I have there the
          8.8.8.8  –Google DNS
          10.0.0.0/24 --NAT LAN
          The gateway IP (ISP gateway)
          public firewall IP
          127.0.0.1

          And this is all the rest of the IPs for the servers that are behind the transparent firewall are not listed here. Should I list them?

          1 Reply Last reply Reply Quote 0
          • ?
            A Former User
            last edited by

            http://forum.pfsense.org/index.php/topic,63589.msg345194.html#msg345194 should have posted this earlier, please see bmeeks's and my posts there. I'm still thinking it's something along those lines.

            1 Reply Last reply Reply Quote 0
            • H
              hypemedia
              last edited by

              Ok is working.

              I have created an alias in firewall > aliases. In the alias I have added all the IPs that I am using behind the transparent firewall.

              Then in Services > snort > whitelist I have created a list called homenetwork and added to the list the alias list from firewall alias list.

              Editing the snort interface I have changed the Home Net from default to the new created list.

              Everything is working now.

              Thanks

              1 Reply Last reply Reply Quote 0
              • ?
                A Former User
                last edited by

                Glad I could help. Snort not working in a transparent bridge is almost guaranteed to be caused by incorrect automatic IP assignments to the variables, just for future google reference.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.