Re: Doubt with Snort and PfSense

Ulises Mora Alvarez via Snort-users <[email protected]> Fri, 2 Aug 2024 12:46:48 -0600
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CANpcZR5F_Uqb4nufiQppjQuOE7O2Ko_JinCZAwoT6PO_HDhiqw@mail.gmail.com>
Hi,

Hello,
Yes, it is possible in the menu
Snort Interfaces > Edit > Interface settings

Once the blocking option is enabled, all alerts will generate blocking of
the IPs that generated the alerts.


[image: Captura de pantalla 2024-08-02 a la(s) 12.36.15 p.m..png]


El vie, 2 ago 2024 a la(s) 11:40 a.m., <[email protected]>
escribió:

> Hello,
>
> sorry for writting again, but nobody has helped me yet.
>
> Is there any way to update all the rules at once so they are in block mode
> instead of in alert mode?
>
> Thanks.
> David
>
>
> -------- Mensaje original --------
> El 18/7/24 19:33, David via Snort-users ha escrito:
>
> Hello,
>
> I already had checked those resources but in none of them I saw how to
> change in all the rules from alert to drop action, something needed as far
> as I understand to really block even if it is working in blocking mode; I
> mean, if I enable blocking mode but the rules are in alert action, no block
> will happen at the end.
>
> Also, note that I am not starting with blocking, I have been working with
> alerts for months to ensure the behaviour.
>
> Thanks!
>
>
> -------- Mensaje original --------
> El 16/7/24 17:52, Ulises Mora Alvarez ha escrito:
>
> Hello.
> This is not the case, I suggest you read the Netgate guide.
> docs.netgate.com
> <https://docs.netgate.com/pfsense/packages/snort/setup.html>
> <https://docs.netgate.com/pfsense/packages/snort/setup.html>
> <https://docs.netgate.com/pfsense/packages/snort/setup.html>
>
> I also suggest a look at this video....
> youtu.be <https://youtu.be/2q_g9GgkvWA>
> <https://youtu.be/2q_g9GgkvWA> <https://youtu.be/2q_g9GgkvWA>
>
> In my experience, when using an IDS/IPS, like Snort, the tricky thing is
> not to start blocking, but to set which alerts should be suppressed and
> which exceptions to put to avoid problem to the users.
> Ulises M. Alvarez
>
> El 16 jul 2024, a la(s) 8:43 a.m., David via Snort-users <
> [email protected]> escribió:
>
> 
> Hi all,
>
> I have enabled and configured Snort in PfSense and now I would like to
> block the offenders, but I see I need to go rule by rule, for each
> category, changing from 'Alert' to 'Drop'. Does anyone know a way to change
> this in all at once?
>
> Thanks.
> _______________________________________________
> Snort-users mailing list
> [email protected]
> Go to this URL to change user options or unsubscribe:
> https://lists.snort.org/mailman/listinfo/snort-users
>
>    To unsubscribe, send an email to:
>    [email protected]
>
> Please visit http://blog.snort.org to stay current on all the latest
> Snort news!
>
> Please follow these rules:
> https://snort.org/faq/what-is-the-mailing-list-etiquette
>
>

-- 
Ulises M. Alvarez
https://sophie.unam.mx/

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
Captura de pantalla 2024-08-02 a la(s) 12.36.15 p.m..png (image/png, 218.3 KB) - not displayed