Categories: Pfsense

Configuring Snort on Pfsense

&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2530 " id&equals;"quads-ad2530" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;<h2 class&equals;"wp-block-heading">Configuring Snort on Pfsense &lpar;will be Updated with the latest version soon&rpar;<&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<p>If you would like to protect your system from any public attacks e&period;g&period; &lpar;Exploits&comma; Transitive trust&comma; Data driven&comma; Infrastructure&comma; DOS&comma; Magic… Etc&period;&rpar; then you should consider deploying IDS or IPS system to detect and protect your network from any attacks&period;<&sol;p>&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2525 " id&equals;"quads-ad2525" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2529 " id&equals;"quads-ad2529" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2528 " id&equals;"quads-ad2528" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;&NewLine;&NewLine;&NewLine;<h2 class&equals;"wp-block-heading">Deploying Snort<&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<p>In Pfsense the famous open source firewall&comma; you have the capability to deploy Snort which is one of the most famous and old ID&sol;PS systems around&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>In order to do so you will have to go to Packages from System&sol;Packages and install it<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort01&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307024&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort01&period;png" alt&equals;""&sol;><&sol;a> &NewLine;&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2531 " id&equals;"quads-ad2531" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine; &NewLine;<&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>After clicking on the packages button&comma; you will get a list of packages and among them snort will be listed there<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort02&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307024&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort02&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Click on the &plus; on the far right to start the installation process&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort03&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307024&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort03&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>I&&num;8217&semi;ll Click on Confirm to continue<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort04&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307024&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort04&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>After it&&num;8217&semi;s been installed now you&&num;8217&semi;ll be able to see it on the Services menu tab&period;<br><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort05&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307024&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort05&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Click on Snort and let&&num;8217&semi;s go configure it&period;<br><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort06&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307024&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort06&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Before you start configuring Snort&comma; you must know that in order to successfully get it to work you must be registered in at least one of the snort communities which publishes important rules that tells snort what to check&period;&period; Similar to the firewall&&num;8217&semi;s rules&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<h2 class&equals;"wp-block-heading">Register on Snort&&num;8217&semi;s Website<&sol;h2>&NewLine;&NewLine;&NewLine;&NewLine;<p>The websites are as following and you can find their settings under the Global settings tab in snort window<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;snort&period;org&sol;users&sol;sign&lowbar;up">https&colon;&sol;&sol;www&period;snort&period;org&sol;users&sol;sign&lowbar;up<&sol;a><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><a href&equals;"https&colon;&sol;&sol;portal&period;emergingthreats&period;net&sol;register">https&colon;&sol;&sol;portal&period;emergingthreats&period;net&sol;register<&sol;a><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort07&period;png" alt&equals;""&sol;><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>I will sign up to Snort free account and configure all of the snort supported rules in order to get the most of it&period; After signing up I&&num;8217&semi;ll need to activate my account&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort08&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort08&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort09&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort09&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>I&nbsp&semi;have&nbsp&semi;receieved the confirmation now and I&&num;8217&semi;ll confirm my account now&comma; Once confirmed Snort will provide you with a code called VRT Oinkmaster confirmation code&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort10&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort10&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>When your account is activated&comma; you will need to go to your profile by clicking on your activated e-mail top right and you will find it on the left side&period; Copy the code and paste it to your snort on pfsense&period;&nbsp&semi;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort11&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort11&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Just like this<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort12&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort12&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>So after I added the code this is how my Global Settings tab looks like&nbsp&semi; &lpar;I enabled all the other free rules as well&rpar;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort13&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort13&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort14&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort14&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Now I will go to Updates tab and start updating rules tab&comma;&nbsp&semi;After clicking update this is how it will look like&colon;&nbsp&semi;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort16&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort16&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>When finished this is how it&&num;8217&semi;ll look like<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort17&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort17&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Back to the updates tab you&&num;8217&semi;ll notice that all the enabled rules have been updated &period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort15&period;png" alt&equals;""&sol;><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>If you are connecting to Pfsense from any location where you are planning to enable Snort Interface for then before you enable snort you must consider going to Pass Lists and add your IP &lpar;Either private if you&&num;8217&semi;re planning to enable the LAN Interface or Public IP if you&&num;8217&semi;re planning to include WAN Interface&rpar;&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort18&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort18&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>In order to create a Pass list&comma; you will have to create an Alias and add the Ips you would like to include in the pass note that these IPS are never going to be checked or filtered by Snort&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>In order to create an Alias List&comma; click on Firewall Tab and scroll to Alias<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort19&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307293&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort19&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Once in IP list page click on the &plus; button far right to add the Ips that you would like to pass&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort20&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307294&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort20&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>From type select the type of hosts that you&&num;8217&semi;d like to include there&comma; for me I&&num;8217&semi;d like to include only a couple of Ips<&sol;p>&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2523 " id&equals;"quads-ad2523" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort21&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307294&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort21&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Click Save and Apply then Close then go back to Snort&&num;8217&semi;s Pass Lists and click on &plus; to add new Pass list&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Select all the Networks&comma; WAN IP&comma; GATEWAY&comma; DNS and finally the Alias that you have created and save&period;&nbsp&semi;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort22&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307294&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort22&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Once saved&comma; this is how the pass lists is going to look like<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort23&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307294&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort23&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Now we can go back to Snort Interfaces and enable the WAN Interface for snort&period; I&&num;8217&semi;ll click on Snort Interfaces tab and click &plus; to add the new interface<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort24&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307294&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort24&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Below I will select block offenders in order to protect myself from DDoS attacks and other attempts to crack internet exposed servers e&period;g&period; &lpar;FTP&comma; Http&period;&period;etc&rpar; &period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort25&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307294&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort25&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort26&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307294&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort26&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Here from Pass List I will select the list which I&&num;8217&semi;ve created in the Pass List tab<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort27&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307294&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort27&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>As you can see below when&nbsp&semi;the icon is red it means that the Snort is not running and you will have to press on the red icon to turn it on&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort28&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307294&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort28&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>After enabling the WAN interface you will have to go define some rules and enable them&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort29&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307294&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort29&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Let&&num;8217&semi;s define some rules for this interface e&period;g&period; FTP in order to do so I will click on the E next to the WAN description far right on the top snapshot&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort30&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307294&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort30&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>We should go to&nbsp&semi;<strong>WAN Categories<&sol;strong>&nbsp&semi;and select different category in order to apply rules&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort38&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307295&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort38&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Note&colon;<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Enabling all rules might affect your VM or PM&&num;8217&semi;s processor performance&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Now I will select all the rules from the rules list below and that will enable all the rules also that are included in the Snort GPLv2 Community&period;&nbsp&semi;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort39&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307295&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort39&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Once added&comma; you will have to apply changes and then click on Apply …&period; And for any reason if the service did not start as in the below snapshot then you should navigate to Status tab and check the &&num;8220&semi;System Logs&&num;8221&semi;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort40&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307295&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort40&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>In System logs I noticed the following error&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>snort&lbrack;13270&rsqb;&colon; FATAL ERROR&colon; &sol;usr&sol;pbi&sol;snort-amd64&sol;etc&sol;snort&sol;snort&lowbar;6026&lowbar;de0&sol;rules&sol;snort&period;rules&lpar;427&rpar; Unknown rule option&colon; &&num;8216&semi;sd&lowbar;pattern&&num;8217&semi;&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort41&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307295&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort41&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>After doing some digging on this error it seems that it&&num;8217&semi;s caused by the rule &&num;8220&semi;Sensitive Data&&num;8221&semi; and after disabling all the rule set in this rule I was able to start Snort on WAN again&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>To disable the rules simply click on the &&num;8220&semi;<strong>Disable all rules in the current Category<&sol;strong>&&num;8221&semi;&nbsp&semi;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort42&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307295&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort42&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>When this is done&comma; I will test snort if it&&num;8217&semi;s working by simply try to hack into pfsense&&num;8217&semi;s portal by using wrong passwords for let&&num;8217&semi;s say 10&sol;20 times and see if my IP will get blocked &lpar;I&&num;8217&semi;ll use a different Public IP which is not in the pass lists&rpar;&period;&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>After trying about 7 attempts with wrong username and password I tried refreshing the page<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort34&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307295&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort34&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>Here is what I got<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort35&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307295&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort35&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>I will go check Snort blocked list and see if the IP that I tried connecting from is there note that the Public IP which I was trying to connect from was<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort36&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307295&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort36&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>As you can see below the IP has been blocked and the alert description&nbsp&semi;says it as it is &lpar;http&lowbar;inspection&rpar;<&sol;p>&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2522 " id&equals;"quads-ad2522" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;&NewLine;&NewLine;&NewLine;<p>So that means that our snort works as it&&num;8217&semi;s supposedly expected to&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><a href&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort37&period;png&quest;attredirects&equals;0"><img src&equals;"http&colon;&sol;&sol;old&period;moh10ly&period;com&sol;&lowbar;&sol;rsrc&sol;1431547307295&sol;blog&sol;pfsense&sol;configuring-snort-on-pfsense&sol;pfsnort37&period;png" alt&equals;""&sol;><&sol;a><&sol;figure>&NewLine;<&sol;p>&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2524 " id&equals;"quads-ad2524" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;

moh10ly

Share
Published by
moh10ly

Recent Posts

Reset passwords for Active Directory Users

Reset and manage your Active Directory users' Passwords Active Directory is one of the most…

3 years ago

Finding Exchange Database hidden mailboxes. ​

Finding Exchange Database hidden mailboxes. Story:Maybe you have been in this situation before, trying to…

3 years ago

Setting up ADConnect and PTA (Password auth through) servers agents behind proxy

If you're using a Proxy server in your firewall or in your network and have…

3 years ago

Get Report of Active Directory Locked Accounts and Machine they logged in from

Story:I got some clients  that have reported some of their users being locked out and…

3 years ago

Checking and Providing Full and SendAs delegate access on O365 Exchange Online

Delegate Permissions This is a code that I have wrote recently to check if an…

3 years ago

Retrieving attachments from Exchange mailbox using python

Story: I got a request from a client who constantly gets CVs and have to…

4 years ago

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298