Snort Not Updating
-
Work at a University. Changed our pfSense from a public IP to a Private (RFC 1918) IP. Now Snort does not update. Any suggestions? I do not see a setting within Snort that would allow this.
-
Your post is not entirely clear. Perhaps it is a language translation issue ???
Are you saying that now your pfSense box is behind some kind of double-NAT? You must eventually have a public IP in order to route traffic (not an RFC 1918 address). However, if your pfSense box now communicates with some upstream host that in turn provides a NAT to some type of public routable IP, then your Snort rules update should still work.
I assume other Internet traffic through the pfSense box works?? Or do you really mean to say you have isolated this pfSense box from the Internet? If that is the case, then there is no method for an offline update in the Snort package. It requires Internet access to update its rules.