Snort ids, ips coverage
-
I have snort on my pfsense lan and wan interface. I have rule to detect and drop vpn traffic and i can see the dropped traffic on the logs.
part of the lan network is an ip towards a linux server serving as internet wifi portal. as this captive portal server (not pfsense captive portal) a part of the lan network of pfsense where snort is monitoring, I assume that any traffic going in and out of the portal ip address is still under the rules of snort on lan interface, right?
therefore, if I block vpn traffic in the pfsense lan network, vpn traffic is also blocked in the wifi portal server and its dhcp clients, right?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.