<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Correctly configuring SNORT to block limewire from the LAN side]]></title><description><![CDATA[<p dir="auto">Hey guys,</p>
<p dir="auto">I've got SNORT humming along, but…I can not get it to block P2P/Limewire stuff.</p>
<p dir="auto">System setup:<br />
P4 2.8Ghz, 1GB DDR-400, 40GB IDE drive.<br />
Software:<br />
PFSense 1.2.3-Release, Snort 2.8.6, 1.27, Squid 2.7.9_1 and Lightsquid 1.7.1, also BandwidthD 2.0.1.2</p>
<p dir="auto">I've enabled SNORT on the WAN interface, manually updating the rules (thanks for the guide RUNE!!) and I can select rulesets.<br />
Rulesets enabled are emerging-p2p and p2p (along with a handful of others covering virus, spyware, scan, exploit etc)</p>
<p dir="auto">I'm hoping to build an all-round decent firewall with IPS detection and caching.</p>
<p dir="auto">Now the problem: Torrenting seems to be blocked now, but I can still fire up Limewire, search and download. I have the block offenders ticked, and when I look in the alerts log I do see things triggered with my WAN port as the source. I get entries in the blocked list if I fire up bitlord and try a download, the hosts are all external IPs, but limewire just keeps going.</p>
<p dir="auto">Can someone please assist me with this? I'm running out of ideas. Once I get this all working I'm intending to replace a Sonicwall (with the security subscriptions configured), but I need this to do the same base functions first :)</p>
<p dir="auto">TIA</p>
<p dir="auto">Joe</p>
]]></description><link>https://forum.netgate.com/topic/25023/correctly-configuring-snort-to-block-limewire-from-the-lan-side</link><generator>RSS for Node</generator><lastBuildDate>Fri, 08 May 2026 15:25:39 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/25023.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 14 Jul 2010 10:37:53 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Correctly configuring SNORT to block limewire from the LAN side on Tue, 20 Jul 2010 20:07:14 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/weselko">@<bdi>weselko</bdi></a>:</p>
<blockquote>
<p dir="auto">First of all PfSense is not a L7 firewall.</p>
</blockquote>
<p dir="auto">It is in 2.0 :-)</p>
]]></description><link>https://forum.netgate.com/post/240326</link><guid isPermaLink="true">https://forum.netgate.com/post/240326</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Tue, 20 Jul 2010 20:07:14 GMT</pubDate></item><item><title><![CDATA[Reply to Correctly configuring SNORT to block limewire from the LAN side on Tue, 20 Jul 2010 20:01:45 GMT]]></title><description><![CDATA[<p dir="auto">Sorry for the OT, but that's a good point; and that's how we treat our users in our office - like adults.  The new hires usually get a brief speech from one of us, to the effect of; we're all adults - complete and unfettered Internet usage isn't a problem unless it becomes a problem and/or we hear something from management.</p>
<p dir="auto">aka - gaming, slacking, surfing YouTube all day isn't our issue - it's a management issue.  Sure, we know who the slackers are - but usually keep quiet unless it's supremely excessive (causes bottlenecks or otherwise becomes disruptive), or management asks.  Sometimes we'll drop hints to a manager…and the problem quickly fixes itself.  Five years of this philosophy has resulted in only ONE person receiving discipline, no viruses, and only token spyware.</p>
<p dir="auto">We're not the Internet police :)  ...every office is different, but it's sure nice to be free of this stuff.</p>
]]></description><link>https://forum.netgate.com/post/240325</link><guid isPermaLink="true">https://forum.netgate.com/post/240325</guid><dc:creator><![CDATA[DigitalJer]]></dc:creator><pubDate>Tue, 20 Jul 2010 20:01:45 GMT</pubDate></item><item><title><![CDATA[Reply to Correctly configuring SNORT to block limewire from the LAN side on Tue, 20 Jul 2010 18:45:35 GMT]]></title><description><![CDATA[<p dir="auto">First of all PfSense is not a L7 firewall. Completly blocking P2P will probably be mission imposible. You can run a tight outgoing policy set with only allowing port 80 and a few other to the outside, but P2P uses http ports as much as any other. What you can do, is use the trafic shaper to slow down P2P to a minimal or use a trafic quota for the users.</p>
<p dir="auto">What I do is allow my users full access, log the trafic and penalize them if theyre breaking the rules. Never had any need to block anything for them since I run that kind of policy.</p>
<p dir="auto">Hope it helps.</p>
]]></description><link>https://forum.netgate.com/post/240310</link><guid isPermaLink="true">https://forum.netgate.com/post/240310</guid><dc:creator><![CDATA[weselko]]></dc:creator><pubDate>Tue, 20 Jul 2010 18:45:35 GMT</pubDate></item><item><title><![CDATA[Reply to Correctly configuring SNORT to block limewire from the LAN side on Fri, 16 Jul 2010 06:53:32 GMT]]></title><description><![CDATA[<p dir="auto">Ah - yes. uPNP is not enabled.</p>
<p dir="auto">I have configured SNORT to scan the WAN interface. Is this correct, or should SNORT be checking the LAN interface for Limewire?</p>
<p dir="auto">Ideally I want things like Limewire (I'm using this as an example, I'd like to block ALL P2P packages) and torrenting etc blocked silently - EG Limewire just doesn't connect without banning the host (Local LAN PC) from the Internet.</p>
<p dir="auto">Any more ideas?</p>
]]></description><link>https://forum.netgate.com/post/239828</link><guid isPermaLink="true">https://forum.netgate.com/post/239828</guid><dc:creator><![CDATA[SnoSalmon]]></dc:creator><pubDate>Fri, 16 Jul 2010 06:53:32 GMT</pubDate></item><item><title><![CDATA[Reply to Correctly configuring SNORT to block limewire from the LAN side on Thu, 15 Jul 2010 15:01:21 GMT]]></title><description><![CDATA[<p dir="auto">In pfsense web gui:</p>
<p dir="auto">Services / UPnP, and ensure the "Enable UPnP" is de-selected.</p>
<p dir="auto">Not sure why Snort isn't blocking, but if for some reason UPnP is enabled, Limewire will happily open up all the ports it needs to communicate.</p>
]]></description><link>https://forum.netgate.com/post/239746</link><guid isPermaLink="true">https://forum.netgate.com/post/239746</guid><dc:creator><![CDATA[DigitalJer]]></dc:creator><pubDate>Thu, 15 Jul 2010 15:01:21 GMT</pubDate></item><item><title><![CDATA[Reply to Correctly configuring SNORT to block limewire from the LAN side on Thu, 15 Jul 2010 10:58:52 GMT]]></title><description><![CDATA[<p dir="auto">DigitalJer is talking about UPnP http://en.wikipedia.org/wiki/Universal_Plug_and_Play not PNP.</p>
]]></description><link>https://forum.netgate.com/post/239684</link><guid isPermaLink="true">https://forum.netgate.com/post/239684</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Thu, 15 Jul 2010 10:58:52 GMT</pubDate></item><item><title><![CDATA[Reply to Correctly configuring SNORT to block limewire from the LAN side on Thu, 15 Jul 2010 10:48:26 GMT]]></title><description><![CDATA[<p dir="auto">PNP is disabled in the BIOS of the PFSense box.<br />
Is there another setting I need to disable or change? PFSense is all default with the exception of the Squid, Lightsquid, BandwidthD and SNORT packages installed.</p>
]]></description><link>https://forum.netgate.com/post/239683</link><guid isPermaLink="true">https://forum.netgate.com/post/239683</guid><dc:creator><![CDATA[SnoSalmon]]></dc:creator><pubDate>Thu, 15 Jul 2010 10:48:26 GMT</pubDate></item><item><title><![CDATA[Reply to Correctly configuring SNORT to block limewire from the LAN side on Thu, 15 Jul 2010 04:24:35 GMT]]></title><description><![CDATA[<p dir="auto">Out of curiosity, do you have UPnP disabled ?</p>
]]></description><link>https://forum.netgate.com/post/239669</link><guid isPermaLink="true">https://forum.netgate.com/post/239669</guid><dc:creator><![CDATA[DigitalJer]]></dc:creator><pubDate>Thu, 15 Jul 2010 04:24:35 GMT</pubDate></item><item><title><![CDATA[Reply to Correctly configuring SNORT to block limewire from the LAN side on Thu, 15 Jul 2010 02:50:15 GMT]]></title><description><![CDATA[<p dir="auto">Bump - Anyone?<br />
Do I need to configure SNORT on the LAN interface instead of the WAN interface?</p>
]]></description><link>https://forum.netgate.com/post/239664</link><guid isPermaLink="true">https://forum.netgate.com/post/239664</guid><dc:creator><![CDATA[SnoSalmon]]></dc:creator><pubDate>Thu, 15 Jul 2010 02:50:15 GMT</pubDate></item></channel></rss>