Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Categories Rulesets - home net help

    Scheduled Pinned Locked Moved IDS/IPS
    2 Posts 2 Posters 786 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • SLIMaxPowerS
      SLIMaxPower
      last edited by

      Slowly working through getting my pfsense setup for a home network.  Its a N36L 16gb ecc (ex freenas setup) 500gb hd, 2 x dual intel nics with one wan + one lan currently.

      On my WAN interface I have 4 rulesets.

      Snort GPLv2 Community Rules (VRT certified) - Enabled

      ET Open Rules - All Enabled/ticked (some rules within unticked as per bmeeks and jflsakfja)

      Snort OpenAppi - All Enabled/ticked (some rules within unticked)

      Snort Text Rules - All Unabled/unticked

      Snort SO Rules - All Unabled/unticked

      The last 2 rulesets don't allow me to tick any of them. When I try I get a red stop sign on the mouse cursor.  Do I need to disable snort on the wan interface first ?

      I did have IPS on WAN set at connectivity but changed to balance. ?

      I am using AC-BNFA-NQ for both WAN and LAN.

      Recommendations please…

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        When you select and enable an IPS Policy, that overrides manual selection of Snort VRT rules – hence the red mouse cursor.  Those checkboxes are disabled by design when using an IPS Policy.  This is because the chosen policy is determining which of those grayed-out categories and rules to use.

        Bill

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.