I think snort is around $30 dollars a year.When I last ran pfsense you do not get any real firewall scanning like firewalla unless you load one of the extra firewall packages on pfsense. Does a Netgate device come loaded with like SNORT or Suricata?
So for $30 per year more the Netgate comes with SNORT loaded? I wonder what Suricata costs?I think snort is around $30 dollars a year.
So, if Netgate does not ship with Snort or Suricata then I would assume all of Netgate's specs are based on running just the router mode without real firewall scanning.You don’t pay for Snort or Suricata in pfsense, they are free to download in package manager as far as I remember. Unless you need to use some specific paid feeds if I’m not mistaken. I’d assume similar in OPNSense.
Netgate sounds just like a pfsense install which I have done many times before in the old days.. A very manual process with no firewall scanning until you install an additional package. When Untangle installs you don't even know when Suricata is installed. Suricata is installed and running with the base Untangle install not like pfsense. A much smoother process.Netgate units come with pre-installed pfSense Plus and not configured. First boot starts the basic configuration screens - LAN IP, user, pass. With business class firewalls no sysadmin expects anything different. Below is available packages lists. They are free to install and run - few clicks in GUI.
Netgate sounds just like a pfsense install
When Untangle installs you don't even know when Suricata is installed.
We will see if they change it to a multi-threaded app and make it better.
Cisco has the power to make Snort better.
If you like he man installs then you are going to really like Cisco command line.
I am not sure this correct. Don't you have to load another package for IPS outbound to work? And then you have to tie them together.Configuration is few clicks now.
You have not told me how outbound scanning and blocking works for malware. Is it on automatically with your couple of clicks?Just to remind you @coxhaus I run pfSense firewall for my home system. I’m trying to help you. Snort has one click automatic configuration rules now. You perhaps have missed a lot of development in recent years. Try it for yourself and make a decision. I’m not forcing you to buy specific hardware, nor use specific software. Everything is documented and easy to read and understand, especially if you already have some networking background.
I had a cousin come over with an infected laptop. Untangle shut it down from getting on the internet. I also had my music server infected when I had someone over to help with their problem laptop. It was the reason I added VLANs to protect my servers in the old days. I can't trust what is going to be on my LAN. People always need help with their PCs. I have a VLAN for untrusted computers devices until I can secure them. So yes, I don't think any network is secure as you never know what is going to show up. How about a hacked wireless? You hope it does not happen but over the years there it has happen with wireless security holes. You want your firewall to shut down out bound connections if they are sending spam or malware.Yes, it can be done in GUI for both Snort and Suricata. I can count the clicks, if it’s very important for you. You don’t need to scan outbound traffic, unless you don’t trust you own network.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!