<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort&#x2F;Suricata Suggestion]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">One of the main feature of pfsense is the ability to use aliases, almost everywhere….and its very well done!!</p>
<p dir="auto">On firewall:Aliases there is 4 tabs; IP, PORT, URL, ALL</p>
<p dir="auto">It would be nice if we could add a 5th tab called: IDS</p>
<p dir="auto">On the IDS tab we could create any meta-variables using the $ operator of Snort or Suricata.</p>
<p dir="auto">Example : $NTP_SERVERS...</p>
<p dir="auto">Any aliases created on this tab could be invoked by IDS rules. That would make Snort and Suricata packages even more accessible, integrate pfsense DNA of aliases and make it even more customizable.</p>
<p dir="auto">F.</p>
]]></description><link>https://forum.netgate.com/topic/76123/snort-suricata-suggestion</link><generator>RSS for Node</generator><lastBuildDate>Tue, 21 Jul 2026 01:54:45 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/76123.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 22 Nov 2014 20:25:34 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Snort&#x2F;Suricata Suggestion on Mon, 24 Nov 2014 16:19:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/fsansfil">@<bdi>fsansfil</bdi></a>:</p>
<blockquote>
<p dir="auto">Hey BBcan,</p>
<p dir="auto">I know, its really well done too…</p>
<p dir="auto">But just wanted a simple way to add more $ operator with aliases ;)</p>
<p dir="auto">F.</p>
</blockquote>
<p dir="auto">This idea would require changes within the pfSense code itself, and not just the Snort or Suricata package code.</p>
<p dir="auto">Bill</p>
]]></description><link>https://forum.netgate.com/post/497257</link><guid isPermaLink="true">https://forum.netgate.com/post/497257</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Mon, 24 Nov 2014 16:19:03 GMT</pubDate></item><item><title><![CDATA[Reply to Snort&#x2F;Suricata Suggestion on Mon, 24 Nov 2014 00:49:12 GMT]]></title><description><![CDATA[<p dir="auto">Hey BBcan,</p>
<p dir="auto">I know, its really well done too…</p>
<p dir="auto">But just wanted a simple way to add more $ operator with aliases ;)</p>
<p dir="auto">F.</p>
]]></description><link>https://forum.netgate.com/post/497183</link><guid isPermaLink="true">https://forum.netgate.com/post/497183</guid><dc:creator><![CDATA[fsansfil]]></dc:creator><pubDate>Mon, 24 Nov 2014 00:49:12 GMT</pubDate></item><item><title><![CDATA[Reply to Snort&#x2F;Suricata Suggestion on Sat, 22 Nov 2014 20:35:40 GMT]]></title><description><![CDATA[<p dir="auto">Hi fsansfil,</p>
<p dir="auto">This functionality already exists with both Snort and Suricata.</p>
<p dir="auto">In each Interface, edit the Interface variables tab (ie "<strong>WAN Variables</strong>"), and enter a pre-defined pfSense Alias.</p>
]]></description><link>https://forum.netgate.com/post/497057</link><guid isPermaLink="true">https://forum.netgate.com/post/497057</guid><dc:creator><![CDATA[BBcan177]]></dc:creator><pubDate>Sat, 22 Nov 2014 20:35:40 GMT</pubDate></item></channel></rss>