• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Snort

When I set up snort facing the internet we had so many false positives I had to really dial it back. Ended up turning it off because it was more trouble than it was worth but I think with some configuration you can make them work okay.

It is useful for reporting if you have it monitoring your local network. Helped me track down a few machines with viruses.
 
Does anyone know an updated GUI like BASE? all of them seem to be years old now. What do you use to monitor your snort?

I know about InstaSnorby but looking for what more people use.
 
When I set up snort facing the internet we had so many false positives I had to really dial it back. Ended up turning it off because it was more trouble than it was worth but I think with some configuration you can make them work okay.

It is useful for reporting if you have it monitoring your local network. Helped me track down a few machines with viruses.

I have snort running on pfsense. It throws out an alert literally every 10-15 second. I dunno if its false or not. It has thrown alerts on the WAN interface on the same ports that my game servers run on behind the firewall. It hasnt affected friends from connecting so I'm ok with it.
 
I have snort running on pfsense. It throws out an alert literally every 10-15 second. I dunno if its false or not. It has thrown alerts on the WAN interface on the same ports that my game servers run on behind the firewall. It hasnt affected friends from connecting so I'm ok with it.

Do you enable all rules?
 
I setup it up on a box a couple of times. Base, OinkMaster, network cards in bridge mode. Wasn't bad, but lots of false positives. Not something you can just drop in and expect instant results.
 
I set up and manage many Snort boxes. After the initial tuning the false positives are pretty low. I primarily use Snort, PulledPork, and Barnyard2. If I can scan the network now and then I will configure and use Hogger.

I've used Base, I've tried Snorby, and used Splunk with the Snort App.
 
I setup snort on my home pfSense. I only have 2 FP: first I disabled through suppress rules, second are on the DNS servers but that doesn't seem to be a problem because they are on a whitelist. You don't want to enable every rule. The are some there to e.g. block any bittorrent traffic.
 
Back
Top