{"id":667,"date":"2022-03-11T11:11:00","date_gmt":"2022-03-11T17:11:00","guid":{"rendered":"https:\/\/techexperiencemx.com\/?p=667"},"modified":"2022-03-09T20:33:18","modified_gmt":"2022-03-10T02:33:18","slug":"snort","status":"publish","type":"post","link":"https:\/\/techexperiencemx.com\/?p=667","title":{"rendered":"Snort"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hola hoy vamos a instalar y configurar snort en Pfsense  pero que es snort?, <strong>Snort es un Sistema de Detecci\u00f3n de Intrusos (IDS)<\/strong>. Implementa un motor de detecci\u00f3n de ataques y&nbsp;escaneo de puertos&nbsp;que permite registrar, alertar y responder ante cualquier anomal\u00eda previamente definida<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Puede funcionar como sniffer y registro de paquetes. Cuando un paquete coincide con alg\u00fan patr\u00f3n establecido en las reglas de configuraci\u00f3n, se logea. As\u00ed se sabe cu\u00e1ndo, de d\u00f3nde y c\u00f3mo se produjo el ataque<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Previamente a instalar Pfsense tendremos que crear un usuario en la pagina oficial de <a href=\"https:\/\/www.snort.org\" data-type=\"URL\" data-id=\"https:\/\/www.snort.org\" target=\"_blank\" rel=\"noopener\">SNORT<\/a> una vez dentro del panel administrador  seleccionamos <mark style=\"background-color:rgba(0, 0, 0, 0);color:#e50a0a\" class=\"has-inline-color\">oinkcode<\/mark> esta sera nuestra llave para configurar mas adelante <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-style-default\"><img loading=\"lazy\" decoding=\"async\" width=\"1394\" height=\"673\" src=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/snort-key-1.png\" alt=\"\" class=\"wp-image-670\" srcset=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/snort-key-1.png 1394w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/snort-key-1-300x145.png 300w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/snort-key-1-1024x494.png 1024w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/snort-key-1-768x371.png 768w\" sizes=\"auto, (max-width: 1394px) 100vw, 1394px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-preformatted\">Nos dirigimos : <mark style=\"background-color:rgba(0, 0, 0, 0);color:#ed0909\" class=\"has-inline-color\">system \/ package manager \/ available packages<\/mark> buscamos snort instalamos <\/pre>\n\n\n\n<pre class=\"wp-block-preformatted\">Nos dirigimos : <mark style=\"background-color:rgba(0, 0, 0, 0);color:#ed0909\" class=\"has-inline-color\">services \/ snort \/ global settings<\/mark><\/pre>\n\n\n\n<pre class=\"wp-block-preformatted\">---snort oinkmaster code\n\n\nagregamos la lleve generada en la pagina snort<\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1135\" height=\"811\" src=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/1-20.png\" alt=\"\" class=\"wp-image-668\" srcset=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/1-20.png 1135w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/1-20-300x214.png 300w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/1-20-1024x732.png 1024w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/1-20-768x549.png 768w\" sizes=\"auto, (max-width: 1135px) 100vw, 1135px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1140\" height=\"632\" src=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/2-3.png\" alt=\"\" class=\"wp-image-672\" srcset=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/2-3.png 1140w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/2-3-300x166.png 300w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/2-3-1024x568.png 1024w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/2-3-768x426.png 768w\" sizes=\"auto, (max-width: 1140px) 100vw, 1140px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">Nos dirigimos : <mark style=\"background-color:rgba(0, 0, 0, 0);color:#f10f0f\" class=\"has-inline-color\">services \/ snort \/ interfaces<\/mark>\n\n\nagregamos las interfaces que queramos que snort empiece a trabajar <\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Elegimos una interfaz  y editamos con l\u00e1piz ejemplo yo seleccion\u00e9 \u00abLan\u00bb <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ahora nos movemos a   \u00ablan categories\u00bb<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1141\" height=\"693\" src=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/3-4.png\" alt=\"\" class=\"wp-image-676\" srcset=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/3-4.png 1141w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/3-4-300x182.png 300w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/3-4-1024x622.png 1024w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/3-4-768x466.png 768w\" sizes=\"auto, (max-width: 1141px) 100vw, 1141px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-preformatted\">Resolve flowbits :  Enable\n\n\n\nUse IPS Policy :  Enable\n\n\n\nIPS Policy Selection : \"connectivity\"    estaya me funciona bien \n\n\n                       \"Balanced\" es la recomendada pero deber\u00e1s tu de probar la que te convenga \n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">Snort GPLv2 Community Rules (Talos certified) : Enable\n\n\n\n<mark style=\"background-color:rgba(0, 0, 0, 0);color:#ef0909\" class=\"has-inline-color\">Enable\tRuleset: ET Open Rules<\/mark> : te recomiendo habilitar todas las de esta linea\n\n\n\n<mark style=\"background-color:rgba(0, 0, 0, 0);color:#e21414\" class=\"has-inline-color\">Ruleset: Snort OPENAPPID Rules<\/mark> : te recomiendo habilitar todas las de esta linea\n\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#ef1515\" class=\"has-inline-color\">nos movemos :  services \/ snort \/ lan interface-settings<\/mark><\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">enable : check enable interface \n\n\nSearch Optimize : enable\n\n\n<mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-ast-global-color-0-color\">ahora vamos a Block Settings<\/mark>\n\n\nBlock Offenders :  Enable <\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1133\" height=\"405\" src=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/4-4.png\" alt=\"\" class=\"wp-image-677\" srcset=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/4-4.png 1133w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/4-4-300x107.png 300w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/4-4-1024x366.png 1024w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/4-4-768x275.png 768w\" sizes=\"auto, (max-width: 1133px) 100vw, 1133px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-preformatted\">IPS MODE :  legacy mode\n\n\nkill states : enable\n\n\nwhich ip to block : DST<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">regresamos a snort interfaces <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1014\" height=\"552\" src=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/5-2.png\" alt=\"\" class=\"wp-image-679\" srcset=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/5-2.png 1014w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/5-2-300x163.png 300w, https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/5-2-768x418.png 768w\" sizes=\"auto, (max-width: 1014px) 100vw, 1014px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">ahora habilitaremos modo bloqueo   <img loading=\"lazy\" decoding=\"async\" width=\"39\" height=\"38\" class=\"wp-image-680\" style=\"width: 39px;\" src=\"https:\/\/techexperiencemx.com\/wp-content\/uploads\/2022\/03\/Captura-de-Pantalla-2022-03-09-a-las-20.13.55.png\" alt=\"boton snort\">   tendremos que prestarle mucha atenci\u00f3n cuando lo habilitemos,  en la secci\u00f3n de \u00abBlocked\u00bb  ya que empezara a bloquear ips (paginas) tendremos que ir agregando a la lista blanca las paginas que sean falsos positivos <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hola hoy vamos a instalar y configurar snort en Pfsense pero que es snort?, Snort es un Sistema de Detecci\u00f3n de Intrusos (IDS). Implementa un motor de detecci\u00f3n de ataques y&nbsp;escaneo de puertos&nbsp;que permite registrar, alertar y responder ante cualquier anomal\u00eda previamente definida Puede funcionar como sniffer y registro de paquetes. Cuando un paquete coincide [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":682,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[16],"tags":[],"class_list":["post-667","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-pfsense"],"_links":{"self":[{"href":"https:\/\/techexperiencemx.com\/index.php?rest_route=\/wp\/v2\/posts\/667","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techexperiencemx.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techexperiencemx.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techexperiencemx.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/techexperiencemx.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=667"}],"version-history":[{"count":0,"href":"https:\/\/techexperiencemx.com\/index.php?rest_route=\/wp\/v2\/posts\/667\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techexperiencemx.com\/index.php?rest_route=\/wp\/v2\/media\/682"}],"wp:attachment":[{"href":"https:\/\/techexperiencemx.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=667"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techexperiencemx.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=667"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techexperiencemx.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=667"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}