Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort in transparent mode

    Scheduled Pinned Locked Moved pfSense Packages
    7 Posts 4 Posters 4.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      m.algoe
      last edited by

      Hi,

      I have tried searching for an answer to the question "Can i use Snort on a pfsense 2.1 box in transparent mode?" but all i find are threads for old versions, or indicating a lot of modifications to configuration files that I'm not 100% comfortable with.

      If yes, are there any good guides/how-tos out there?

      1 Reply Last reply Reply Quote 0
      • F
        Fesoj
        last edited by

        What do you mean? Snort is not a proxy like squid.

        1 Reply Last reply Reply Quote 0
        • M
          m.algoe
          last edited by

          Exactly, it analyses traffic passing through the firewall and blocks bad traffic. It should be capable of doing so when pfSense is in transparent (bridged) mode as well, just as you can add firewall rules on a transparent box.

          1 Reply Last reply Reply Quote 0
          • F
            Fesoj
            last edited by

            pfSense is essentially a router, which is never transparent. Clients need to have a proper gateway address. Squid, the web proxy, can bei either transparent or opaque (requiring special browser settings).

            Snort itself is rather passive and reports only. When you use additional software like spoink or snortsam, there is some feedback mechanism that modifies the firewall to block offenders.

            Maybe this helps a bit to sort out how things work together.

            1 Reply Last reply Reply Quote 0
            • D
              dhatz
              last edited by

              pfSense can be deployed and is being deployed in "transparent" bridge mode, not only as a router.

              Whether pfSense's snort-package can work correctly in such a configuration, I'm not quite sure though …

              1 Reply Last reply Reply Quote 0
              • F
                Fesoj
                last edited by

                Yes, there are other threads dealing with this topic and "System: Advanced: System Tunables" has a few parameters that contain the word "bridge". I have a few APs running as plain bridges, but never thought of using pfSense as a bridge. At least I understand now to some degree why this setup could make any sense  :)

                1 Reply Last reply Reply Quote 0
                • C
                  cmb
                  last edited by

                  Snort listens on network interface(s). It doesn't matter if they're bridged, routed, NATed, or just a span port from a switch that isn't involved in moving/filtering the traffic of the network at all. It's all the same.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.