CARP rules show up as "part" of the snort package in rules.debug
This is only a cosmetic change, but it adds a header to the generated rules to separate it from the snort package. See https://github.com/pfsense/pfsense/pull/4486 for details.
#3 Updated by Danilo Zrenjanin 5 months ago
- Status changed from Feedback to Resolved
2.5.0-DEVELOPMENT (amd64) built on Sat Nov 21 01:03:32 EST 2020 FreeBSD 12.2-STABLE
Indeed it looks better now:
# Snort package block log quick from <snort2c> to any tracker 1000000118 label "Block snort2c hosts" block log quick from any to <snort2c> tracker 1000000119 label "Block snort2c hosts" # CARP rules block in log quick proto carp from (self) to any tracker 1000000201 pass quick proto carp tracker 1000000202 no state