Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suggestion on snort please. (SOLVED)

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 417 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W Offline
      whitekalu
      last edited by whitekalu

      Hello friends.
      I am getting lot of random incoming connection trying to get into my home network and pfsense is dropping all of them can snort be configured as fail2ban like "IF 2 failed connection attempt from IP: XX.XX.XX.XX block it for xx HR/DAY ?
      Is there other package available to do this task as I can see there is no fail2ban package.
      Thankyou

      1 Reply Last reply Reply Quote 0
      • bmeeksB Offline
        bmeeks
        last edited by bmeeks

        Snort actually passes off blocking to the firewall, so if pfSense is already blocking the offenders as you say, what's the point of something like fail2ban? How would two blocks help in this case?

        Tools such as fail2ban are for hosts that are generally forced to take incoming connections in order to do their job. Think a mail server. It pretty much has to take any incoming SMTP request in order to route mail. Now, if you have a malicious client repeatedly making SMTP connections to your mail server, then something like fail2ban is useful as it will stop that malicious host but not others.

        Your case is quite different according to your explanation. You have a host attempting to make a connection to you and pfSense is blocking the attempt. That's all you need. Fail2ban would just be redundant and not afford you anything additional.

        1 Reply Last reply Reply Quote 1
        • W Offline
          whitekalu
          last edited by

          Hi bmeeks
          Thank you for the response. Indeed pfSense is doing it's job great.
          I'm clear about the scenario now.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.