Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort blocking

    pfSense Packages
    3
    3
    1.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      Guest
      last edited by

      Hi
      I want to know how pfsense snort package block attacking hosts. Is there a plugin like snortsam in snort package?

      1 Reply Last reply Reply Quote 0
      • J
        Jack-proteclouth
        last edited by

        This is already built into the snort package, open the interface settings in snort and tick 'Block Offenders'
        You can also select if you want to block src/dst or both & if you want to kill firewall states for the blocked IP.

        EDIT:
        In the snort global settings there is also the option to set how often you want to remove blocks (E.g. 1hour, 1day, 28days, never, etc)

        1 Reply Last reply Reply Quote 0
        • bmeeksB
          bmeeks
          last edited by

          @Amirkabir:

          Hi
          I want to know how pfsense snort package block attacking hosts. Is there a plugin like snortsam in snort package?

          Snort on pfSense makes use of an old third-party open-source plugin called Spoink.  This is compiled into the Snort binary on pfSense as an output plugin.  It sees all of the alerts and examines the IP addresses and compares them to an internal whitelist table.  Any IP address not matching up with a whitelist entry is then "blocked".  This blocking is done by calling the BSD pf (packet filter) API to insert the offending IP address into a block table called snort2c.  Currently snortsam is not used.

          Bill

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.