Did I configure snort properly?
-
Hey guys,
I have snort active on WAN/LAN/AND OPT1. I read around, and some people only have it for WAN. Should I only set snort active on WAN only?
Also, if I have a port open on my firewall, and snort has it as blacklisted, will snort override my firewall rules? Just a general question.
Thanks guys!
-
Most of snorts rules are designed to block against attacks coming over the internet… so unless you expects attacks to come from friendly's, I'd just enable it on the WAN.
Regarding your second question, yes, the firewall rule created by snort should block traffic from that IP altogether, however I have noticed some inconsistencies with pfsense and firewall rules (particularly that if you're using squid, firewall rules over port 80 don't work). You should do some testing to make sure it behaves as you expect.