Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Did I configure snort properly?

    pfSense Packages
    2
    2
    1511
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mechanicalmetal last edited by

      Hey guys,

      I have snort active on WAN/LAN/AND OPT1. I read around, and some people only have it for WAN. Should I only set snort active on WAN only?

      Also, if I have a port open on my firewall, and snort has it as blacklisted, will snort override my firewall rules? Just a general question.

      Thanks guys!

      1 Reply Last reply Reply Quote 0
      • J
        JustinHoMi last edited by

        Most of snorts rules are designed to block against attacks coming over the internet… so unless you expects attacks to come from friendly's, I'd just enable it on the WAN.

        Regarding your second question, yes, the firewall rule created by snort should block traffic from that IP altogether, however I have noticed some inconsistencies with pfsense and firewall rules (particularly that if you're using squid, firewall rules over port 80 don't work). You should do some testing to make sure it behaves as you expect.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post