Re: Doubt with Snort and PfSense

Ulises Mora Alvarez via Snort-users <[email protected]> Tue, 16 Jul 2024 09:52:45 -0600
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Hello.

This is not the case, I suggest you read the Netgate guide.

docs.netgate.com

https://docs.netgate.com/pfsense/packages/snort/setup.html

I also suggest a look at this video....

youtu.be

https://youtu.be/2q_g9GgkvWA

In my experience, when using an IDS/IPS, like Snort, the tricky thing is not to start blocking, but to set which alerts should be suppressed and which exceptions to put to avoid problem to the users.

Ulises M. Alvarez

El 16 jul 2024, a la(s) 8:43 a.m., David via Snort-users <[email protected]> escribió:


Hi all,

I have enabled and configured Snort in PfSense and now I would like to block the offenders, but I see I need to go rule by rule, for each category, changing from 'Alert' to 'Drop'. Does anyone know a way to change this in all at once?

Thanks.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

To unsubscribe, send an email to:
[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette