Snort destination LAN IP

  • Currently, I have Snort setup on pfSense with the Connectivity IPS policy (block src and dst). Everything works as it should, however, the issue that I'm having is that when Snort blocks something, I can only see my WAN address and the address of the remote server. Is there a way for me to see the local LAN IP that caused the alert (or was the target of the attack), to see if one of my computers got infected or is misbehaving?

  • The only way is to run snort also in LAN (as I do). I use the same rules for both WAN and LAN. There is a long sticky thread with some advises on that.