How we use PFsense with Snort & PFblockerNG

Поділитися
Вставка
  • Опубліковано 27 січ 2025

КОМЕНТАРІ • 25

  • @kanes5105
    @kanes5105 4 роки тому +3

    Thanks for all the videos you have done on pfSense, very easy to understand and follow along. Cheers!

  • @Dorff_Meister
    @Dorff_Meister 3 роки тому +1

    Thanks for the intro to the video going over some of the options... I'm setting my first pfSense instance and some of these were things I wanted to change but hadn't found them yet. I also setup Notifications with Telegram which was a snap (I'm using a telegram bot for another project so adding a second was super easy).

  • @JasonLeaman
    @JasonLeaman 3 роки тому

    Thank you for this ! Going to try this on Pfsense 2.5.

  • @drreality1
    @drreality1 4 роки тому +2

    Great one, thank you.
    Keep going

  • @muhammadaamir566
    @muhammadaamir566 Рік тому

    How to exclude a external public IP/specific IP on WAN side from snort in pfsense?

  • @chrisspatgen
    @chrisspatgen 4 роки тому +1

    Thank you for the very informative video. I currently have pfBlockerNG, Suricata and Snort w/Subscription installed. I was wondering since pfBlockerNG checks both IP addresses and FQDN’s why do I need Snort or Suricata, they only filter on IP addresses. I understand that each of the installed programs have different rules sets, I assume pfBlockerNG would have a larger rule set then both Snort and Suricata combined, so pfBlockerNG makes Snort and Suricata redundant? Thoughts, comments?

  • @ramzez_uk
    @ramzez_uk 3 роки тому

    Great video and as usual greatly delivered content. I was wondering if you planning on doing a Suricata video on a 2.5.2 setup? Many thanks.

    • @ramzez_uk
      @ramzez_uk 3 роки тому

      also I have followed the guy, but even sites like speediest are blocked now, is there a good list of rules which don't do that?

  • @mikescott4008
    @mikescott4008 3 роки тому +1

    What's your views on Untangle or Sophos XG, as for the home setup they're in the similar space. I originally started with pfsense, but wanted more Layer7 capabilities. I'm probably re-installing pfsense at some point as you're more likely to see it than Sophos XG or Untangle in the commercial space. A fellow Hampshire resident :)

  • @almost1234
    @almost1234 4 роки тому

    Can you elaborate more on the DNSBL showing disabled even though it is enabled in settings? I am having this issue now and can't seem to find the solution anywhere.

  • @j.c.5011
    @j.c.5011 3 роки тому

    You have "OpenVPN" selected as an outbound interface. Isn't it an inbound interface, especially when connected to your VPN server running on Pfsense? I that case you would be remotely logging in on your Pfsense. Would seem like an inbound interface to me rather then outbound.

  • @drreality1
    @drreality1 4 роки тому +1

    Is it possible to do a separate tutorial on s an no snort please.
    Cheers

  • @1337kaas
    @1337kaas 4 роки тому

    Thanks, Will take a look at these utilities. Very interesting stuff

  • @matldn2697
    @matldn2697 4 роки тому

    I cannot use speed test websites after installing Snort. Any help??

    • @FrimleyComputing
      @FrimleyComputing  4 роки тому

      Use the snort reporting to find what's being blocked and then you can allow the access by either removing the snort rule or adding a supress action on the blocked request to allow it.

    • @matldn2697
      @matldn2697 4 роки тому

      @@FrimleyComputing Thanks, I am completely new to Snort. Where is "snort reporting" and how do I allow speed test . net ?

    • @matldn2697
      @matldn2697 4 роки тому

      Any help??

    • @FrimleyComputing
      @FrimleyComputing  4 роки тому +1

      @@matldn2697 The very first thing you should do is go to the INTERFACE SETTINGS tab for the interfaces where you have Snort running and turn off blocking. Then go to the BLOCKS tab and click the Clear button to remove all Snort blocks. Run with blocking disabled for several weeks to gauge your network traffic patterns, to see what types of false positives are happening, and to tune the rule sets you select. Only after you have tuned your rules and created necessary suppression lists (or disabled those rules entirely as appropriate) should you enable blocking again.
      Next, go read the official documentation here: docs.netgate.com/pfsense/en/latest/packages/snort/setup.html. That will show you how to configure the package, and most importantly, show you how to find alerts, blocks and Suppression Lists.
      Hope you manage to get things sorted. :-)

    • @matldn2697
      @matldn2697 4 роки тому

      @@FrimleyComputing Thanks. I will do that.

  • @muhammadaamir566
    @muhammadaamir566 4 роки тому

    How I will by pass my IP from pfBlocker?

  • @solsats
    @solsats 4 роки тому

    Great Video 👍 Thanks.. Are you using a 6 port or 4 port partaker type device by any chance? Rgds

  • @umairmalik4865
    @umairmalik4865 4 роки тому

    can you please tell me how to block torrent or b2b in pfsens ??

  • @m4chinesuniverse552
    @m4chinesuniverse552 4 роки тому

    awesome

  • @paulvancyber1979
    @paulvancyber1979 4 роки тому

    my pfblockerNG is different than yours :o