Snort Inline drop/reject and pass/alert in rules
-
Hi,
I have:
pfsense: 2.6.0
snort: 4.1.6 (IPS mode: Inline)I'm trying to apply two rules, e.g. (this is just a simple example):
pass icmp 192.168.0.10 any -> any any (msg:"CUSTOM ping"; sid:9990007;)
drop icmp any any -> any any (msg:"CUSTOM ping"; sid:9990008;)I always have all ip blocked (also 192.168.0.10).
I want to block all traffic except selected IP addresses.
What rules should I save for this to work properly?
Any help is welcome.
Regards
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.