Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Using snort & suricata

    IDS/IPS
    3
    6
    1.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      fantasypoo
      last edited by

      Hi, is it a bad idea to use Snort for VRT and Suricata for ET ? 
      Or should I just use one package.

      Thx

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        You can use both but only ONE of them can have blocking enabled. Given the overhead with this (maintenance, system resources) I really think it's better to stick to one.

        1 Reply Last reply Reply Quote 0
        • F
          fantasypoo
          last edited by

          hmm both of them have blocking 'enabled'..  unless one of them isn't actually blocking as you say!

          ![pfsense1.jpg
          ![pfsense1.jpg_thumb

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks
            last edited by

            Both use the same pf table to implement blocking, so if you enable blocking on both packages they will conflict with each other.  As @doktornotor stated, choose one of the packages and use just that one.  No advantage to using both.

            Bill

            1 Reply Last reply Reply Quote 0
            • F
              fantasypoo
              last edited by

              Thanks!  I removed suricata.

              1 Reply Last reply Reply Quote 0
              • F
                fantasypoo
                last edited by

                I found this amusing –

                "pfblocker is the gate in the fence, snort is the more paranoid security guard checking papers for the stuff that was allowed through the gate."

                I was thinking I would have two security guards using snort and suricata! .. but I guess that isn't really the case.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.