Snort blocks pfSense ip
-
Is it possible to NOT block the pfSense LAN ip with Snort when using the "Block offenders" option?
I want the rest of the network to be blocked, but when Snort blocks the src/dst ip now it also blocks access from LAN to the firewall.
Ideally you can only access pfSense to unblock yourself again. -
It would be even better if Snort would obey the "Anti Lockout Rule" in pfSense.
Placing the blocked ip's as a firewall rule instead of just blocking would already be enough. -
You have the option to add IPs or networks to a whitelist in Snort.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.