Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort custom rules/config?

    Scheduled Pinned Locked Moved pfSense Packages
    9 Posts 3 Posters 3.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      geoffmyers
      last edited by

      Hi everyone,

      Sorry in advance if this has been answered.  I did spend some time searching for the answer before asking so don't completely flame me.

      Two questions, similar topic:

      1. Is there a way to config the aliases used in the snort rules.  For instance $HOME_NET $EXTERNAL_NET….. ETC.  Seems like this would allow a big performance boost to those who are having issues.

      2. Is there a way to include other rulesets besides those available from Snort.org, such as the bleeding rules?

      Thanks,

      -Geoff

      1 Reply Last reply Reply Quote 0
      • ? This user is from outside of this forum
        Guest
        last edited by

        Currently the snort package only supports updating signatures from an oinkmaster server.  People have asked for bleeding snort support before, but nobody's submitted any patches for it yet.

        1 Reply Last reply Reply Quote 0
        • G Offline
          geoffmyers
          last edited by

          And about the aliases?

          1 Reply Last reply Reply Quote 0
          • ? This user is from outside of this forum
            Guest
            last edited by

            No, I don't believe there is a way to do this either in the current package.

            1 Reply Last reply Reply Quote 0
            • G Offline
              geoffmyers
              last edited by

              Is it ok to just modify the snort.conf file, or will that hose everything?

              1 Reply Last reply Reply Quote 0
              • S Offline
                sullrich
                last edited by

                @geoffmyers:

                Is it ok to just modify the snort.conf file, or will that hose everything?

                Sure but it will be overwritten on every bootup.  Search the forum for more information on this.

                1 Reply Last reply Reply Quote 0
                • G Offline
                  geoffmyers
                  last edited by

                  Heh.. 3 posts and I'm already a 'go search the forum newb'.  Thanks for the responses.  I do appreciate them.

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    sullrich
                    last edited by

                    @geoffmyers:

                    Heh.. 3 posts and I'm already a 'go search the forum newb'.

                    Sorry but this has been gone over in quite a lot of detail.  Far more detail than I care to spend posting it yet again and or explaining myself again.  That IS what the search function is for.  Nothing personal.

                    1 Reply Last reply Reply Quote 0
                    • G Offline
                      geoffmyers
                      last edited by

                      NP

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.