<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort in transparent mode]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I have tried searching for an answer to the question "Can i use Snort on a pfsense 2.1 box in transparent mode?" but all i find are threads for old versions, or indicating a lot of modifications to configuration files that I'm not 100% comfortable with.</p>
<p dir="auto">If yes, are there any good guides/how-tos out there?</p>
]]></description><link>https://forum.netgate.com/topic/48862/snort-in-transparent-mode</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Jul 2026 07:25:41 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/48862.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 24 Sep 2012 14:56:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Snort in transparent mode on Sat, 13 Oct 2012 00:51:52 GMT]]></title><description><![CDATA[<p dir="auto">Snort listens on network interface(s). It doesn't matter if they're bridged, routed, NATed, or just a span port from a switch that isn't involved in moving/filtering the traffic of the network at all. It's all the same.</p>
]]></description><link>https://forum.netgate.com/post/359985</link><guid isPermaLink="true">https://forum.netgate.com/post/359985</guid><dc:creator><![CDATA[cmb]]></dc:creator><pubDate>Sat, 13 Oct 2012 00:51:52 GMT</pubDate></item><item><title><![CDATA[Reply to Snort in transparent mode on Wed, 10 Oct 2012 13:44:40 GMT]]></title><description><![CDATA[<p dir="auto">Yes, there are other threads dealing with this topic and "System: Advanced: System Tunables" has a few parameters that contain the word "bridge". I have a few APs running as plain bridges, but never thought of using pfSense as a bridge. At least I understand now to some degree why this setup could make any sense  :)</p>
]]></description><link>https://forum.netgate.com/post/359614</link><guid isPermaLink="true">https://forum.netgate.com/post/359614</guid><dc:creator><![CDATA[Fesoj]]></dc:creator><pubDate>Wed, 10 Oct 2012 13:44:40 GMT</pubDate></item><item><title><![CDATA[Reply to Snort in transparent mode on Wed, 10 Oct 2012 12:42:34 GMT]]></title><description><![CDATA[<p dir="auto">pfSense can be deployed and is being deployed in "transparent" bridge mode, not only as a router.</p>
<p dir="auto">Whether pfSense's snort-package can work correctly in such a configuration, I'm not quite sure though …</p>
]]></description><link>https://forum.netgate.com/post/359599</link><guid isPermaLink="true">https://forum.netgate.com/post/359599</guid><dc:creator><![CDATA[dhatz]]></dc:creator><pubDate>Wed, 10 Oct 2012 12:42:34 GMT</pubDate></item><item><title><![CDATA[Reply to Snort in transparent mode on Wed, 10 Oct 2012 09:47:17 GMT]]></title><description><![CDATA[<p dir="auto">pfSense is essentially a router, which is never transparent. Clients need to have a proper gateway address. Squid, the web proxy, can bei either transparent or opaque (requiring special browser settings).</p>
<p dir="auto">Snort itself is rather passive and reports only. When you use additional software like spoink or snortsam, there is some feedback mechanism that modifies the firewall to block offenders.</p>
<p dir="auto">Maybe this helps a bit to sort out how things work together.</p>
]]></description><link>https://forum.netgate.com/post/359582</link><guid isPermaLink="true">https://forum.netgate.com/post/359582</guid><dc:creator><![CDATA[Fesoj]]></dc:creator><pubDate>Wed, 10 Oct 2012 09:47:17 GMT</pubDate></item><item><title><![CDATA[Reply to Snort in transparent mode on Wed, 10 Oct 2012 09:30:06 GMT]]></title><description><![CDATA[<p dir="auto">Exactly, it analyses traffic passing through the firewall and blocks bad traffic. It should be capable of doing so when pfSense is in transparent (bridged) mode as well, just as you can add firewall rules on a transparent box.</p>
]]></description><link>https://forum.netgate.com/post/359581</link><guid isPermaLink="true">https://forum.netgate.com/post/359581</guid><dc:creator><![CDATA[m.algoe]]></dc:creator><pubDate>Wed, 10 Oct 2012 09:30:06 GMT</pubDate></item><item><title><![CDATA[Reply to Snort in transparent mode on Tue, 25 Sep 2012 09:09:43 GMT]]></title><description><![CDATA[<p dir="auto">What do you mean? Snort is not a proxy like squid.</p>
]]></description><link>https://forum.netgate.com/post/357391</link><guid isPermaLink="true">https://forum.netgate.com/post/357391</guid><dc:creator><![CDATA[Fesoj]]></dc:creator><pubDate>Tue, 25 Sep 2012 09:09:43 GMT</pubDate></item></channel></rss>