#security
-
pfSense Suricata vs Snort: Which IDS/IPS to Choose
Suricata suits most pfSense homelabs with multithreading, EVE JSON logs and Snort rules. Choose Snort for OpenAppID, then stage IDS before inline IPS.
-
pfSense GeoIP Blocking with pfBlockerNG and MaxMind
Add a MaxMind license key for GeoLite2 country blocks, choose inbound or outbound actions, then add Emerging Threats, Spamhaus and Abuse.ch feeds.
-
pfBlockerNG Setup on pfSense: DNSBL and Threat Blocking
This pfBlockerNG setup guide covers DNSBL feeds, resolver enforcement, IP reputation, false-positive tuning, testing, and rollback on pfSense.