RFC (make up a number not in use) - Blueprint for setting up snort + pfblocker
-
So in future, I can copy all the forced rules off= GID:SID from within <rule_sid_off>to</rule_sid_off>
Then paste on the old config.xml file, if I have somehow lost the configuration setting in Snort for
configuring FALSE positives??? :)You are correct. Copying and pasting the section you have highlighted will preserve the disabled rules.
Bill
-
Thanks bmeeks ;D
If there is any future update in Snort package, e.g. right now is 2.9.7.0 pkg v3.2.3 ,
say there is a newer version = 2.9.8.0 pkg v3.4.0 and I proceed to update.Does the update reset the disable rules and then goes back to the default settings??? ::)
-
Thanks bmeeks ;D
If there is any future update in Snort package, e.g. right now is 2.9.7.0 pkg v3.2.3 ,
say there is a newer version = 2.9.8.0 pkg v3.4.0 and I proceed to update.Does the update reset the disable rules and then goes back to the default settings??? ::)
No, updates to the package will remember and use all of your current settings so long as you have the checkbox ticked on the GLOBAL SETTINGS tab to "keep settings on deinstall". I've made that default to "checked" on new green field installs, but you can double check on your setup to insure the checkbox is checked.
Bill
-
The first post in this thread for the snort set up was in 2013, is that information for inital setup still valid ?
I am a noob to pFSense and just got mine up and running and just now about to install Snort for the first time
-
@ninjaneer:
The first post in this thread for the snort set up was in 2013, is that information for inital setup still valid ?
I am a noob to pFSense and just got mine up and running and just now about to install Snort for the first time
I'm not far behind you…. but I have been using it for a couple years and have just had to revisit it as health issues kept me from spending the time to update to the new versions under 2.2.4. But I'll say this is very close to still ringing true, some minor differences that I was able to work around in pfBlocker, Snort and the Rules setup. My Thanks to Bill for his help getting my system back up. I'm still tweaking on it a bit everyday.
I'd love to see Demetris update this but I know he is very deep into Suricata and he too is recovering from a serious health issue.
On that note... while rebuilding my aliases, I discovered many of the lists I had used were either abandoned, had slight name changes or were just no longer available.
Does anyone who really stays current have a good group of the current blocklists they import they would care to post??
Thanks,
Rick -
If you don't mind me asking (stupidly): What's the point of this?
Can't I just enable all and be done with it?! Is this just for a few MB's of ram savings? -
If you don't mind me asking (stupidly): What's the point of this?
Can't I just enable all and be done with it?! Is this just for a few MB's of ram savings?While there are certainly some RAM savings (mine were significant), it has more to do with settings and processing behaviors. The OP also had a deep understanding of the rules and their history and knew which rules were old and obsoleted and which new rules were causing false positives.
Yep, you can turn them all on… expect some problems getting to things.
But depending on your needs and places you go you'll find yourself doing some tweaking anyway.
-
The missing emerging-dhsield ip list might be this url?
http://feeds.dshield.org/top10-2.txt -
It's relevant for me too, thank you for explanation
-
This post is deleted!