Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Working with snort

    pfSense Packages
    2
    4
    1.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      amrogers3
      last edited by

      Hello all,

      I plan on utilizing Snort but I am waiting on developers to get the package working. In the meantime, I have a few questions.

      I am not sure how Snort works on the pfSense firewall. I plan on using VLANs on my install.

      Does pfSense Snort package allow you to monitor each interface?  Can you select to individually monitor WAN, LAN, each VLAN? or does it only monitor incoming traffic?

      Thanks in advance for the help.

      1 Reply Last reply Reply Quote 0
      • C
        Cino
        last edited by

        You can attach Snort to any interface you want. Before it broke, i had my WAN, LAN, WLAN_Guest (This is a VLAN), WAN_3G interfaces bind to it. The more interfaces and rules you enable, the more memory and horsepower it will use.

        1 Reply Last reply Reply Quote 0
        • A
          amrogers3
          last edited by

          @Cino:

          You can attach Snort to any interface you want. Before it broke, i had my WAN, LAN, WLAN_Guest (This is a VLAN), WAN_3G interfaces bind to it. The more interfaces and rules you enable, the more memory and horsepower it will use.

          Thanks very much for reply Cino. So if I understand correctly, I can specifically designate Snort to analyze traffic only on LAN?

          1 Reply Last reply Reply Quote 0
          • C
            Cino
            last edited by

            Yes… You dont have to have it on the WAN...

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.