IDS/IPS / Wildcard Suppress list
January 19, 2018, 08:59:03 pm

We receive a large amount of the same group alerts

ET CINS Active Threat Intelligence Poor Reputation IP TCP group 97

This always is group 97, 98,34,34  ect

Is there a way to suppress this alert without adding each one one by one ?


ET CINS Active Threat Intelligence Poor Reputation IP TCP  *.*

Firewalling / Outbound SYN and Excluding VM from PFsense
January 18, 2018, 06:21:46 am
First of all let me start by saying pfsense if brilliant.

It has taken months to get right but now it is secure and blocking all nasties.

2 things I need advise on.

1. Can pfsense manage to restrict outbound SYN Flooding
2. How do we go about excluding a particular VM and IP from the firewall and pfblocker rules ?

Thank you for a wonderful product!!!

General Questions / Whitelist IP behind Pfsense
January 01, 2018, 10:45:27 am
We have pretty strict reputation rules for all machines behind pfsense however we are moving our website behind pfsense however we still want bad reputation IPs to visit our website. Is it possible a have some internal IPs to be whitelisted so traffic desitned for those IPs are not blocked by snort or pfblocker ?

Naturally we want other rules applied but it is just the reputation and possible the tor traffic to still reach our website.


