Does Snort Inline Blocking Effect All Interfaces?
-
One thing I've been confused about as I dive into Snort more in pfSense is the blocking modes. In most cases I'd prefer to have inline since it can stop packets before any get to the destination, however, inline mode is described in a lot of posts as being in between the host stack and the "physical interface".
I'm curious if enabling this impacts more VLANs or if it just impacts the selected VLAN I have Snort running on in this environment.
Any ideas?
On an additional note, does this change require a reboot or anything along those lines?
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.