Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rules for WAN or LAN?

    Scheduled Pinned Locked Moved IDS/IPS
    4 Posts 2 Posters 883 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pfcode
      last edited by

      HI,

      Am I right thinking that rules with $EXTERNAL_NET as source are for WAN, and rules with $HOME_NET as source are for LAN?  Trying to enable/disable rules for WAN and LAN interfaces for Snort/Suricata, going to disable all the $EXTERNAL_NET source rules for LAN, and disable all the $HOME_NET source rules for WAN?

      Thanks,

      Release: pfSense 2.4.3(amd64)
      M/B: Supermicro A1SRi-2558F
      HDD: Intel X25-M 160G
      RAM: 2x8Gb Kingston ECC ValueRAM
      AP: Netgear R7000 (XWRT), Unifi AC Pro

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        No, $EXTERNAL_NET and $HOME_NET simply define networks that are to be protected ($HOME_NET) and those that are considered "the enemy" ($EXTERNAL_NET).

        Bill

        1 Reply Last reply Reply Quote 0
        • P
          pfcode
          last edited by

          @bmeeks:

          No, $EXTERNAL_NET and $HOME_NET simply define networks that are to be protected ($HOME_NET) and those that are considered "the enemy" ($EXTERNAL_NET).

          Bill

          Thanks much,  How do I do so that on the Alerts screen I can see WAN address as Destination for incoming alerts, and LAN addresses as source for outgoing alerts?

          Release: pfSense 2.4.3(amd64)
          M/B: Supermicro A1SRi-2558F
          HDD: Intel X25-M 160G
          RAM: 2x8Gb Kingston ECC ValueRAM
          AP: Netgear R7000 (XWRT), Unifi AC Pro

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks
            last edited by

            The addresses in the packets themselves determine source versus destination.  Maybe I am misunderstanding what you are wanting.

            Perhaps what you are asking is how to see alerts so that the WAN is not the only HOME_NET address shown.  To do that, you must run Snort on the LAN interface.  Only there can it display addresses before the NAT rules are applied.

            Do a search here on the forum for "snort wan vs lan" and you should get some threads to look through.

            Bill

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.