Re: Seeking Recommendations for Snort Implementation in pfSense
"Michael Matirko \(mmatirko\) via Snort-users" <[email protected]> Thu, 13 Jun 2024 18:27:44 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <MN2PR11MB35656D5B36642FA29699F2CCCAC12@MN2PR11MB3565.namprd11.prod.outlook.com> |
Hi, To the best of my knowledge, we don’t currently have any resources specifically tailored to Snort on pfSense. In general however, with my experience using Snort on pfSense, the configuration of Snort rules should be pretty similar to Snort in any other environment. The first thing to do is to make sure you’ve selected the correct IPS policy and rules, since a more security-oriented policy will result in more (possibly false positive) rule hits. Additionally, you should be able to select the rulesets that you wish Snort to load on startup. Depending on your or your customers’ network setups, certain parts of these rulesets may lead to more false positives than others, so they can be modified or disabled as required. Individual rules can also be disabled if desired. The pfSense guide for the Snort package<https://docs.netgate.com/pfsense/en/latest/packages/snort/setup.html> seems to include the steps for most of the above. For understanding the rules themselves, we do have a few guides: Anatomy of a Snort Rule Infographic<https://snort-org-site.s3.amazonaws.com/production/document_files/files/000/000/116/original/Snort_rule_infographic.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAU7AK5ITMMOXGB2W5%2F20240613%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20240613T171851Z&X-Amz-Expires=172800&X-Amz-SignedHeaders=host&X-Amz-Signature=86271301dd9282e2d590d7184a40f8dfa12181a04ffcee61441fb9602cda3926> “Writing Snort Rules” Section of the Snort2 Manual<http://manual-snort-org.s3-website-us-east-1.amazonaws.com/node27.html> There are a few others that may be helpful on our official resources page<https://snort.org/documents#OfficialDocumentation>, as well. Hope this is able to help a bit. Thanks, Mike From: Snort-users <[email protected]> on behalf of Manuel J. Silva Mira via Snort-users <[email protected]> Date: Thursday, June 13, 2024 at 10:27 AM To: [email protected] <[email protected]> Subject: [Snort-users] Seeking Recommendations for Snort Implementation in pfSense Hi, This is my first email to this list, and I hope I'm doing it right. I manage IT maintenance for several clients, and Snort is essential for my security protocols. I have implemented Snort on their pfSense firewalls, which I manage. However, I haven’t delved deeply into Snort’s rule setup and technology. Consequently, my configurations on pfSense often result in numerous false positives. In my own company, it’s relatively easy for me to address and manage these alerts. However, dealing with frequent calls from users in other companies regarding false positives is not ideal. My questions are: Does snort.org offer any resources or support specifically for pfSense Snort implementations that could help bridge my knowledge gap? Can anyone recommend comprehensive documentation or resources that would help me better understand how to configure Snort to minimize false positives? Would it be worthwhile to consider a one-hour service support session from pfSense for Snort, or should I look into other professional services for more in-depth assistance? I appreciate any guidance or recommendations you can provide. Com os melhores cumprimentos - Best Regards - Mit Freundliche Grüße - Saludos, Manuel J. Silva Mira _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette