I'm wondering if there is a feature that allows to drop an inbound packet on an external interface by content of the packet.
E.g., iptables has such functionality but it's Linux software. I'm on FreeBSD 10.2 and I use PF as a firewall; PF doesn't have such feature.
It seems security/suricata might do it in the IPS mode but it requires switching from PF to IPFW in order to operate.
Could someone give me advice?
E.g., iptables has such functionality but it's Linux software. I'm on FreeBSD 10.2 and I use PF as a firewall; PF doesn't have such feature.
It seems security/suricata might do it in the IPS mode but it requires switching from PF to IPFW in order to operate.
Could someone give me advice?