One way snort and WAN

  • Hello, I'm using stop to detect intrusions on my pfsense firewall. Snort is setup on the Wan interface. I'd like to fire alerts only when intruders are coming from the outside. For instance, I don't want to throw an alert if somebody inside the network tries to access a website, only for incoming connections from the net. Is it possible ?

Log in to reply