Seeking Recommendations for Snort Implementation in pfSense
"Manuel J. Silva Mira via Snort-users" <[email protected]> Wed, 12 Jun 2024 20:33:25 +0100
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Organization | CRM-line |
| Message-ID | <!&!AAAAAAAAAAAYAAAAAAAAAHj50XTmJwBGkwCinIW7QwXCgAAAEAAAAA9EWd8r5PdAvhD0uAz/[email protected]> |
Hi, This is my first email to this list, and I hope I'm doing it right. I manage IT maintenance for several clients, and Snort is essential for my security protocols. I have implemented Snort on their pfSense firewalls, which I manage. However, I havent delved deeply into Snorts rule setup and technology. Consequently, my configurations on pfSense often result in numerous false positives. In my own company, its relatively easy for me to address and manage these alerts. However, dealing with frequent calls from users in other companies regarding false positives is not ideal. My questions are: Does snort.org offer any resources or support specifically for pfSense Snort implementations that could help bridge my knowledge gap? Can anyone recommend comprehensive documentation or resources that would help me better understand how to configure Snort to minimize false positives? Would it be worthwhile to consider a one-hour service support session from pfSense for Snort, or should I look into other professional services for more in-depth assistance? I appreciate any guidance or recommendations you can provide. Com os melhores cumprimentos - Best Regards - Mit Freundliche Grüße - Saludos, Manuel J. Silva Mira _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette