Seeking Recommendations for Snort Implementation in pfSense

"Manuel J. Silva Mira via Snort-users" <[email protected]> Wed, 12 Jun 2024 20:33:25 +0100
Newsgroups gmane.comp.security.ids.snort.general
Organization CRM-line
Message-ID <!&!AAAAAAAAAAAYAAAAAAAAAHj50XTmJwBGkwCinIW7QwXCgAAAEAAAAA9EWd8r5PdAvhD0uAz/[email protected]>
Hi,

 

This is my first email to this list, and I hope I'm doing it right.

 

I manage IT maintenance for several clients, and Snort is essential for my
security protocols. I have implemented Snort on their pfSense firewalls,
which I manage. However, I haven’t delved deeply into Snort’s rule setup and
technology. Consequently, my configurations on pfSense often result in
numerous false positives.

 

In my own company, it’s relatively easy for me to address and manage these
alerts. However, dealing with frequent calls from users in other companies
regarding false positives is not ideal.

 

My questions are:

 

Does snort.org offer any resources or support specifically for pfSense Snort
implementations that could help bridge my knowledge gap?

Can anyone recommend comprehensive documentation or resources that would
help me better understand how to configure Snort to minimize false
positives?

Would it be worthwhile to consider a one-hour service support session from
pfSense for Snort, or should I look into other professional services for
more in-depth assistance?

I appreciate any guidance or recommendations you can provide.

 

Com os melhores cumprimentos - Best Regards - Mit Freundliche Grüße -
Saludos,

 

Manuel J. Silva Mira

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette