Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort - transfer config from one port to another?

    Scheduled Pinned Locked Moved pfSense Packages
    6 Posts 3 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Q
      q54e3w
      last edited by

      Is there an easy way to copy a snort configuration from one WAN port to another port - copy some .conf file somehow? Anything other than go through the ruleset one by one to save time would be appreciated, thanks in adv for any tips

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        Not currently, but Bill Meeks is working on this functionality for both the Snort and Suricata Packages in the upcoming releases.

        https://forum.pfsense.org/index.php?topic=76137.15#lastPost

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • Q
          q54e3w
          last edited by

          thanks for the prompt response. I'll grab some beers and start setting up then….second thoughts, might be best to lay off the beer whilst setting up snort rules  :o

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks
            last edited by

            @irj972:

            thanks for the prompt response. I'll grab some beers and start setting up then….second thoughts, might be best to lay off the beer whilst setting up snort rules  :o

            Updated:
            This capability is coming in the next Snort update.  The Pull Request will be posted in the next day or two is now posted for review and merging by the pfSense Core Team.  The feature will work like duplicating firewall rules based on a existing one.  You will have plus (+) icons next to each configured Snort interface.  Clicking the icon will create a new Snort instance on the next available interface and bring over all the settings from the source except for the interface name and the Suppress List, Pass List, Home Net and External Net settings.  Those revert to defaults.

            Here is the link to the Pull Request: https://github.com/pfsense/pfsense-packages/pull/661

            Bill

            1 Reply Last reply Reply Quote 0
            • bmeeksB
              bmeeks
              last edited by

              @BBcan17:

              Not currently, but Bill Meeks is working on this functionality for both the Snort and Suricata Packages in the upcoming releases.

              https://forum.pfsense.org/index.php?topic=76137.15#lastPost

              The Pull Request containing this functionality for Suricata is posted here https://github.com/pfsense/pfsense-packages/pull/659

              Snort is coming in the next day or two.

              Bill

              1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator
                last edited by

                @irj972:

                thanks for the prompt response. I'll grab some beers and start setting up then….second thoughts, might be best to lay off the beer whilst setting up snort rules  :o

                As long as you are still drinking beers when you turn Snort back on ….  :)

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.