Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort/Suricata Suggestion

    pfSense Packages
    3
    4
    988
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      fsansfil
      last edited by

      Hello,

      One of the main feature of pfsense is the ability to use aliases, almost everywhere….and its very well done!!

      On firewall:Aliases there is 4 tabs; IP, PORT, URL, ALL

      It would be nice if we could add a 5th tab called: IDS

      On the IDS tab we could create any meta-variables using the $ operator of Snort or Suricata.

      Example : $NTP_SERVERS...

      Any aliases created on this tab could be invoked by IDS rules. That would make Snort and Suricata packages even more accessible, integrate pfsense DNA of aliases and make it even more customizable.

      F.

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        Hi fsansfil,

        This functionality already exists with both Snort and Suricata.

        In each Interface, edit the Interface variables tab (ie "WAN Variables"), and enter a pre-defined pfSense Alias.

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • F
          fsansfil
          last edited by

          Hey BBcan,

          I know, its really well done too…

          But just wanted a simple way to add more $ operator with aliases ;)

          F.

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks
            last edited by

            @fsansfil:

            Hey BBcan,

            I know, its really well done too…

            But just wanted a simple way to add more $ operator with aliases ;)

            F.

            This idea would require changes within the pfSense code itself, and not just the Snort or Suricata package code.

            Bill

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.