Thread: Snort IPS IPFW
View Single Post
Old 13th September 2015
denta denta is offline
Shell Scout
 
Join Date: Nov 2009
Location: Sweden
Posts: 95
Default

Quote:
Originally Posted by Peter_APIIT View Post
General protection. I don't have any web server, database server not ftp or sshd.
So basically, it sounds like the packets that would trigger snort alerts would have been blocked by pf anyway. Perhaps an alternative is the pf overload <table> statement, which allows you to automatically block certain IP:s, without the added effort and security risks of running snort on your external interface(s).
Reply With Quote