Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense and Snort

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      Edem
      last edited by

      I have installed Pfsense and installed the snort package. I activated snort and applied all snort ruleset,
      ET Open Rules, Snort Text Rules and  Snort SO Rules, save and made sure snort is running. But after this when i open Microsoft outlook and do a send / receive, i get an error message saying POP3 error cannot connect to mail server 0x80042108. when i stopped snort from running,  outlook send/receive now works fine without this error message. I want to continue using snort and keep all rule sets activated but doing this affects Microsoft outlook ,Can someone please help.

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        @Edem:

        I have installed Pfsense and installed the snort package. I activated snort and applied all snort ruleset,
        ET Open Rules, Snort Text Rules and  Snort SO Rules, save and made sure snort is running. But after this when i open Microsoft outlook and do a send / receive, i get an error message saying POP3 error cannot connect to mail server 0x80042108. when i stopped snort from running,  outlook send/receive now works fine without this error message. I want to continue using snort and keep all rule sets activated but doing this affects Microsoft outlook ,Can someone please help.

        You can't just install Snort, download rules, and enable blocking.  If you do that, you get what happened to you – blocking of legitimate traffic.  If you are new to using Snort, go to the Packages sub-forum and click on the sticky thread at the top which shows you how to configure it.  There is also a thread on suggested Suppress List entries to prevent some of the most common false-positive alerts.

        Here is the Quick Setup thread: https://forum.pfsense.org/index.php?topic=61018.0
        And here is the Master Suppress List thread: https://forum.pfsense.org/index.php?topic=56267.0

        Bill

        1 Reply Last reply Reply Quote 1
        • E
          Edem
          last edited by

          Thanks Bill for your reply. I was on holiday out at a remote location so could not response quickly. I will check the material and see if it would help me set this up quickly. Do you also have any literature on how to setup IDS and IPS with snort.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.