Quote from: ldanna1945 on October 03, 2025, 12:39:43 AMSo far I have Zenarmor and GEOIP blocking installed and working. Thoughts on intrusion protection and adding Clamav to the firewall.
GeoIP won't save you from pipe DoS, nor provides any actual security on the WAN side. GeoIP really only works by protecting LAN to WAN traffic. GeoIP cuts out some noise, but if hackers target you, they will not be in any of your GeoIP blocking rules. ;)
Run bogons, and suricata (ET Pro Telemetry). ClamAV is mediocre at best, and it wont help when all your traffic is under TLS. Any AV that runs on freeBSD will help protect the fw itself, but pick something better than clam. Maybe rkhunter is better (https://www.freshports.org/security/rkhunter), free and it's made to look for the stuff that would normally land on the system. "AV" is perhaps too broad for fw device. So install rkh, setup as specified. The daily check seems plausible since it's not a realtime scanner (realtime AV tools take resources to watch file writes or reads, which is impactful on any system, and is why you see more times than not many areas of the system are configured in AV to be ignored, not good).