Home page logo

snort logo Snort mailing list archives

Newb Question
From: Josh Bitto <jbitto () onlineschool ca>
Date: Tue, 21 May 2013 09:38:10 -0700

I'm using pfsense and I haven't turned on blocking yet. So to kind of tell you what my setup is I have a wan interface 
and then internal interfaces......So I usually just want to turn on blocking from source...Is there a way to exclude my 
wan interface IP from being blocked? My worry is that if there is something outbound as the wan interface as being the 
source IP that snort would block it. Then I inadvertently have blocked service to my users. Which is something I want 
to avoid. Am I over thinking this?

Try New Relic Now & We'll Send You this Cool Shirt
New Relic is the only SaaS-based application performance monitoring service 
that delivers powerful full stack analytics. Optimize and monitor your
browser, app, & servers with just a few lines of code. Try New Relic
and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_may
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

Please visit http://blog.snort.org to stay current on all the latest Snort news!

  By Date           By Thread  

Current thread:
  • Newb Question Josh Bitto (May 21)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]