SwampKracker
Senior Member
YesFor you guys that run pfsense do you run IPS/IDS on pfsense? If not then Firewalla will be a higher level firewall because they run some kind of IPS/IDS.
I am trying to figure out if pfsense users really use SNORT etc.
YesFor you guys that run pfsense do you run IPS/IDS on pfsense? If not then Firewalla will be a higher level firewall because they run some kind of IPS/IDS.
I am trying to figure out if pfsense users really use SNORT etc.
I don't see Talos on the list. I see Spamhaus, Dshield, and iblocklist.com.I don't do IPS/IDS as it requires SSL decryption on router side, in order to work properly.
However, I use pfblocker that creates firewall IP lists using feeds from Talos, Spamhaus and many more.
It aslo creates rules for porn and ad blocking. This combined with Quad9 for malware, creates a very powerful DNS firewall.
It has a Talos-Snort list.I don't see Talos on the list. I see Spamhaus, Dshield, and iblocklist.com.
Packages — pfBlocker-NG Package | pfSense Documentation (netgate.com)
Talos is Cisco.
Threat Protection in OSI layer 7 is lacking in pfsense. I don't believe you can block at the application layer. You have to block at lower levels. I don't believe you can add block Facebook on pfsense. At least I don't remember it.
My understanding is you need to pay for Talos lists and you need to run SNORT which you said you didn't run SNORT only pfBlocker.It has a Talos-Snort list.
It is true that it cannot block an app on layer7.
However, you can add a feed from github that contain let's say Facebook's list of domains and IPs and you can block them on firewall and on DNS level. Here is an example.
@avtella - are you able to expand on this at all? I seem to be back and forth quite a bit between the ease of installation vs long term reliability between Firewalla and a Netgate pfsense box (4100/6100).I would probably recommend this over pfsense for new users,
Firewalla is a consumer product. It's made easy for people with no much networking knowledge. Will they survive on the competitive consumer market is unknown. Netgate has different target customers and pfSense is different application product. No direct comparison between the two.
New Years Eve, really?
what do you recommend
and what do you use
I'm using Netgate 5100 appliance with pfSense for about 4 years already. It has Gigabit ports, but good enough for my home network.
but pf/opn sense and OpenWRT failed to do so
Suuure... you have to run something no longer available.

Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!