<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort LAN interface assignment]]></title><description><![CDATA[<p dir="auto">I don't know if this is of concern also. My Lan interface assignment to snort only detects the destination as the firewall and not listing the Wan IP it is trying to access after this update. Prior to the update most often listed the LAN and the WAN and did not list the firewall as the destinations.</p>
<p dir="auto">Has anyone else noticed this?</p>
]]></description><link>https://forum.netgate.com/topic/183220/snort-lan-interface-assignment</link><generator>RSS for Node</generator><lastBuildDate>Sun, 19 Jul 2026 00:09:21 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/183220.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 05 Oct 2023 02:28:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Snort LAN interface assignment on Thu, 05 Oct 2023 22:38:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jonathanlee">@<bdi>JonathanLee</bdi></a> said in <a href="/post/1128604">Snort LAN interface assignment</a>:</p>
<blockquote>
<p dir="auto">So should I move it to wan side because of no access to inline mode?</p>
</blockquote>
<p dir="auto">No, not in my view. And Inline Mode or not Inline Mode has zero bearing on where you should run the IDS/IPS.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jonathanlee">@<bdi>JonathanLee</bdi></a> said in <a href="/post/1128604">Snort LAN interface assignment</a>:</p>
<blockquote>
<p dir="auto">Do you know what official negate appliance supports inline mode?</p>
</blockquote>
<p dir="auto">Any of their non-Marvel switched ports appliances. Examples include SG-5100, SG-6100, SG-8200, and a few others. Look at the list of netmap compatible devices I posted earlier.</p>
]]></description><link>https://forum.netgate.com/post/1128606</link><guid isPermaLink="true">https://forum.netgate.com/post/1128606</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Thu, 05 Oct 2023 22:38:20 GMT</pubDate></item><item><title><![CDATA[Reply to Snort LAN interface assignment on Thu, 05 Oct 2023 22:32:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bmeeks">@<bdi>bmeeks</bdi></a> So should I move it to wan side because of no access to inline mode? My current config can see the xbox wan side addresses.</p>
<p dir="auto">Do you know what official negate appliance supports inline mode?</p>
]]></description><link>https://forum.netgate.com/post/1128604</link><guid isPermaLink="true">https://forum.netgate.com/post/1128604</guid><dc:creator><![CDATA[JonathanLee]]></dc:creator><pubDate>Thu, 05 Oct 2023 22:32:05 GMT</pubDate></item><item><title><![CDATA[Reply to Snort LAN interface assignment on Thu, 05 Oct 2023 22:30:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jonathanlee">@<bdi>JonathanLee</bdi></a> said in <a href="/post/1128602">Snort LAN interface assignment</a>:</p>
<blockquote>
<p dir="auto">Is there a way to see the NAT or where the lan clients want to go after the firewall?</p>
</blockquote>
<p dir="auto">No, look at the other posts where I have posted the diagrams of how network traffic flows when using one of the IDS/IPS packages. The IDS/IPS sits directly between the physical NIC and the rest of the operating system kernel. It can't see anything beyond what is contained in the packet as it comes off the NIC (or from the operating system network stack on the way to the physical NIC).</p>
<p dir="auto">It has no idea, nor any way to find out, what the operating system's network stack does with the packets.</p>
]]></description><link>https://forum.netgate.com/post/1128603</link><guid isPermaLink="true">https://forum.netgate.com/post/1128603</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Thu, 05 Oct 2023 22:30:19 GMT</pubDate></item><item><title><![CDATA[Reply to Snort LAN interface assignment on Thu, 05 Oct 2023 22:25:14 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bmeeks">@<bdi>bmeeks</bdi></a></p>
<p dir="auto"><img src="/assets/uploads/files/1696544662791-screenshot-2023-10-05-at-3.23.59-pm-resized.png" alt="Screenshot 2023-10-05 at 3.23.59 PM.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">They all show traversal to the proxy or firewall IP.</p>
<p dir="auto">Is there a way to see the NAT or where the lan clients want to go after the firewall?</p>
]]></description><link>https://forum.netgate.com/post/1128602</link><guid isPermaLink="true">https://forum.netgate.com/post/1128602</guid><dc:creator><![CDATA[JonathanLee]]></dc:creator><pubDate>Thu, 05 Oct 2023 22:25:14 GMT</pubDate></item><item><title><![CDATA[Reply to Snort LAN interface assignment on Thu, 05 Oct 2023 13:14:42 GMT]]></title><description><![CDATA[<p dir="auto">Show a screen capture of what you are talking about. What you posted is not clear. What do you mean by WAN IP? Do you mean the literal public IP address assigned to your firewall, or do you really mean an external IP (as in totally outside your local networks)?</p>
]]></description><link>https://forum.netgate.com/post/1128497</link><guid isPermaLink="true">https://forum.netgate.com/post/1128497</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Thu, 05 Oct 2023 13:14:42 GMT</pubDate></item></channel></rss>