Snort mailing list archives

Re: Snort-sigs Digest


From: wkitty42--- via Snort-sigs <snort-sigs () lists snort org>
Date: Fri, 31 May 2019 15:25:06 -0400

On 5/30/19 10:59 AM, konstantinos dimos via Snort-sigs wrote:
Hi I am new to snort and I need to ask the following. I have a pc with three
NIC cards.One for WAN one for LAN and one for DMZ. I need to install pfsense
with snort installed. How do I configure snort to listen to the three
interfaces?

pfsense should handle the snort configuration... if they configure it to listen on more than one interface, then it should be fairly easy to do... snort should be part of the pfsense package if they offer it as one of the monitoring services... you'll be looking to pfsense support for more information on this... especially if they are bundling snort with pfsense...

FWIW: unless something has changed in recent times, you'll have three separate snort instances running, one for each interface... each one will have a specific ID associated with it to keep the alerts separated...


--
 NOTE: No off-list assistance is given without prior approval.
       *Please keep mailing list traffic on the list unless*
       *a signed and pre-paid contract is in effect with us.*
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" 
https://snort.org/downloads/#rule-downloads";>emerging threats</a>!


Current thread: