Re: [pfSense] Snort as IPS in Pfsense

2014-09-29 Thread Josh Bitto
Of course you canIt's an add-on. -Original Message- From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Roberto Carna Sent: Monday, September 29, 2014 10:28 AM To: list@lists.pfsense.org Subject: [pfSense] Snort as IPS in Pfsense Dear, I need to know if it's possible to se

[pfSense] High Memory Usage

2013-05-31 Thread Josh Bitto
We have been using snort for a couple of months now and we are starting to see that the memory usage for each interface is 672 mb's per interface. According to the documentation that I have read the interfaces should only be going up to 200 mb's. Is that correct? I've tweaked the rules selecte

Re: [pfSense] Remote Syslog Problem

2013-05-28 Thread Josh Bitto
My question would be why are you opening and closing your vpn tunnel. The other thing you might consider is just doing a cron job to restart the service. -Original Message- From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Nishant Sharma Sent: T

[pfSense] Snort Package and vlans's

2013-05-15 Thread Josh Bitto
I'm running the latest snort package on pfsense and for the most part its working. The wan interface works and I can see traffic particularly src and dest IP's.That's fineI'm now into doing internal interfaces and I did a test to see if traffic picks up from vlan interfaces by doing a po

[pfSense] Snort on Pfsense

2013-05-13 Thread Josh Bitto
I was wondering if anyone uses snort on pfsense. The reason I ask is when I select the rule sets for a particular interface there are 3 policy options to choose. OR You can disable that and choose which rules you want to activate. To my understanding setting the "policy" option automatically use

[pfSense] possible DNS-rebind attack detected

2013-05-10 Thread Josh Bitto
Hello, I'm getting in my system logs the following: firewall dnsmasq[35138]: possible DNS-rebind attack detected: okanagan.bc.ca Is this something to worry about? I've looked at the forums and most people say to disable the rebind option in the system settings. I'm kinda concerned if this is a

Re: [pfSense] IP subnet confusion

2013-04-08 Thread Josh Bitto
This is your friend http://www.aelius.com/njh/subnet_sheet.html Have you played around with different subnet masks to see if you know for sure it's a mask issue? From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Jason T. Slack-Moehrle Sent: Monday,

[pfSense] Snort and CPU usage on pfsense

2013-02-18 Thread Josh Bitto
I'm curious to hear. Is snort still only single threaded on a CPU or have newer versions allowed it to run on more than one core? What I need is to make sure I have enough machine to run my WAN and about 4 VLANs. Each would have an interface to monitor, but where I'm stuck is the rule sets...

[pfSense] Creating User for Snort

2013-02-15 Thread Josh Bitto
Is there a way to create a user that only has access to the installed package snort? Happy Friday! ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

[pfSense] Sending Email Alerts

2013-02-14 Thread Josh Bitto
Is there a way to send email alerts from Pfsense/Snort Package to an email address when a rule fires? Or just one email if there is multiple rules that trigger so I don't get hit with hundred's of emails. Josh ___ List mailing list List@lists.pfsense.o

Re: [pfSense] Snort and multiple vlans

2013-02-13 Thread Josh Bitto
From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Ugo Bellavance Sent: Tuesday, February 12, 2013 4:45 PM To: list@lists.pfsense.org Subject: Re: [pfSense] Snort and multiple vlans On 2013-02-12 15:41, Josh Bitto wrote: > I've read the documentati

[pfSense] Snort and multiple vlans

2013-02-12 Thread Josh Bitto
I've read the documentation on snort not working really that well with vlansIs there anyone out there that has been successful with this? ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

[pfSense] Snort

2013-02-05 Thread Josh Bitto
Does anyone use snort on their firewall? I'm looking up documentation on unblocking IP's manually. So far I haven't found anything on either Snort's website or pfsense website. ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailm

[pfSense] Snort and SQL data

2013-02-01 Thread Josh Bitto
on PFsense On Thu, Jan 31, 2013 at 11:01 PM, Josh Bitto mailto:jbi...@onlineschool.ca>> wrote: Does anyone have any experience putting snort on your pfsense box and having the alerts sent to a sql database? I need help setting up the sql part Check the forums and Web for barnyard2(on

[pfSense] Snort and SQL on PFsense

2013-01-31 Thread Josh Bitto
Does anyone have any experience putting snort on your pfsense box and having the alerts sent to a sql database? I need help setting up the sql part ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

[pfSense] Snort and PFsense/Proxmox

2013-01-29 Thread Josh Bitto
Hello People, I'm having trouble with snort starting on pfsenseI get a message that says"php:/ status_services:php: The command '/usr/local/etc/rc.d/snort.sh stop' returned exit code '1', the output was " I get this anytime that I try and start the service.I can include my whole s