PFSense Packet Filtering by Hex/String?

  • I apologize if this has been posted before, I can't seem to find a use case thats similar to mine. Today, I got hit with my first DDoS attack on my new network. My other one is a colocation where they provide me the tools necessary to write my firewall rules. I have been using bfp rules before, such as - ip[28:4]=0xffffffff and ip[36:4]=0x0a303030, for blocking UDP packets.

    On this network, I use PFSense as my firewall and I am trying to figure out where I can go to write similar rules. I looked through the L7-filter rules briefly, prior to posting this but to date I am still unsure what I need to be doing, it does appear to do hex packets, but I am unclear as to why I can't state which bytes the hex data should reside in. I would appreciate it if someone can point me in the right direction.

  • Banned

    Uhm… no. You may try Snort/Suricata.

Log in to reply