When trying to use the advanced option 'Maximum number of established connections per host', users get blocked, but I see nothing on the 'virusprot' table or any other table.
For testing, I set a ridiculous small number (5) and of course, I cannot get a single webpage... so it is working, but I want/need to see the list of trapped people.
Even with the default hour of the cron to remove blocked users, I haven't found a way of 'monitoring' this function.
Am I missing something? is snort a requirement to see users in 'virusprot' table?
I'm using the last stable PfSense (2.0.1) in a box with several VLANs. I set the rule just in one Vlan for testing.
Thanks in advance!