<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort Blocking]]></title><description><![CDATA[<p dir="auto">Hello Everyone,</p>
<p dir="auto">I have recently switched to pfSnese from IPCop.  I am loving the change so far!</p>
<p dir="auto">I have configured Snort with blocking on my firewall.  I would like to exclude some rules from automatic blocking.  Some rules, such as the Shellcode ones generate quite a bit of false positives in my implementation.  I am not able to find a way to do this in the GUI.  The host whitelist feature won't work for me because there are too many.  I also don't want to suppress the noisy rules because I would like to see the alerts and investigate manually.  I was going to edit the configuration files and was hoping that someone can point me in the right direction.  My questions are:</p>
<p dir="auto">1.  Which snort.conf does the Snort package use in pfSense?  I have two, /usr/local/etc/snort/snort.conf and /usr/local/etc/snort/snort_14918_bge0/snort.conf?</p>
<p dir="auto">2. This directive seems to be ignored:  portvar SHELLCODE_PORTS !80.  Does pfSense not use this VAR or is there something wrong with my config?</p>
<p dir="auto">3.  Where does pfSense configure blocking in Snort?</p>
<p dir="auto">Thanks in advance!</p>
]]></description><link>https://forum.netgate.com/topic/41906/snort-blocking</link><generator>RSS for Node</generator><lastBuildDate>Sat, 06 Jun 2026 02:30:07 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/41906.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 11 Feb 2012 17:13:32 GMT</pubDate><ttl>60</ttl></channel></rss>