Re: Doubt with Snort and PfSense
Ulises Mora Alvarez via Snort-users <[email protected]> Tue, 16 Jul 2024 09:52:45 -0600
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Hello. This is not the case, I suggest you read the Netgate guide. docs.netgate.com https://docs.netgate.com/pfsense/packages/snort/setup.html I also suggest a look at this video.... youtu.be https://youtu.be/2q_g9GgkvWA In my experience, when using an IDS/IPS, like Snort, the tricky thing is not to start blocking, but to set which alerts should be suppressed and which exceptions to put to avoid problem to the users. Ulises M. Alvarez El 16 jul 2024, a la(s) 8:43 a.m., David via Snort-users <[email protected]> escribió: Hi all, I have enabled and configured Snort in PfSense and now I would like to block the offenders, but I see I need to go rule by rule, for each category, changing from 'Alert' to 'Drop'. Does anyone know a way to change this in all at once? Thanks. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette