Skip to main content
Lab 6.3.4: Implement Intrusion Prevention [WLOs: 3, 4] [CLOs: 3, 4]
- Sign in to the pfSense management console.
- In the Username field, enter admin.
- In the Password field, enter P@ssw0rd (zero).
- Select SIGN IN or press Enter.
- Access the Snort Global Settings.
- From the pfSense menu bar, select Services > Snort.
- Under the Services breadcrumb, select Global Settings.
- Configure the required rules to be downloaded.
- Select Enable Snort VRT.
- In the Sort Oinkmaster Code field, enter 359d00c0e75a37a4dbd70757745c5c5dg85aa. You can copy and paste this from the scenario.
- Select Enable Snort GPLv2.
- Select Enable ET Open.
- Configure the Sourcefire OpenAppID Detectors to be downloaded.
- Under Sourcefire OpenAppID Detectors, select Enable OpenAppID.
- Select Enable RULES OpenAppID.
- Configure when and how often the rules will be updated.
- Under Rules Update Settings, use the Update Interval drop-down menu to select 1 Day.
- For Update Start Time, change to 01:00.
- Select Hide Deprecated Rules Categories.
- Configure Snort General Settings.
- Under General Settings, use the Remove Blocked Hosts Interval drop-down menu to select 1 HOUR.
- Select Startup/Shutdown Logging.
- Select Save.
- Configure the Snort Interface settings for the WAN interface.
- Under the Services breadcrumb, select Snort Interfaces and then select Add.
- Under General Settings, make sure Enable interface is selected.
- For Interface, use the drop-down menu to select WAN (CorpNet_pfSense_L port 1).
- For Description, use WANSnort.
- Under Alert Settings, select Send Alerts to System Log.
- Select Block Offenders.
- Scroll to the bottom and select Save.
- Start Snort on the WAN interface.
- Under the Snort Status column, select the arrow.
- Wait for a checkmark to appear, indicating that Snort was started successfully.
Comments
Post a Comment