Re: Doubt with Snort and PfSense
Ulises Mora Alvarez via Snort-users <[email protected]> Fri, 2 Aug 2024 12:46:48 -0600
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CANpcZR5F_Uqb4nufiQppjQuOE7O2Ko_JinCZAwoT6PO_HDhiqw@mail.gmail.com> |
Hi, Hello, Yes, it is possible in the menu Snort Interfaces > Edit > Interface settings Once the blocking option is enabled, all alerts will generate blocking of the IPs that generated the alerts. [image: Captura de pantalla 2024-08-02 a la(s) 12.36.15 p.m..png] El vie, 2 ago 2024 a la(s) 11:40 a.m., <[email protected]> escribió: > Hello, > > sorry for writting again, but nobody has helped me yet. > > Is there any way to update all the rules at once so they are in block mode > instead of in alert mode? > > Thanks. > David > > > -------- Mensaje original -------- > El 18/7/24 19:33, David via Snort-users ha escrito: > > Hello, > > I already had checked those resources but in none of them I saw how to > change in all the rules from alert to drop action, something needed as far > as I understand to really block even if it is working in blocking mode; I > mean, if I enable blocking mode but the rules are in alert action, no block > will happen at the end. > > Also, note that I am not starting with blocking, I have been working with > alerts for months to ensure the behaviour. > > Thanks! > > > -------- Mensaje original -------- > El 16/7/24 17:52, Ulises Mora Alvarez ha escrito: > > Hello. > This is not the case, I suggest you read the Netgate guide. > docs.netgate.com > <https://docs.netgate.com/pfsense/packages/snort/setup.html> > <https://docs.netgate.com/pfsense/packages/snort/setup.html> > <https://docs.netgate.com/pfsense/packages/snort/setup.html> > > I also suggest a look at this video.... > youtu.be <https://youtu.be/2q_g9GgkvWA> > <https://youtu.be/2q_g9GgkvWA> <https://youtu.be/2q_g9GgkvWA> > > In my experience, when using an IDS/IPS, like Snort, the tricky thing is > not to start blocking, but to set which alerts should be suppressed and > which exceptions to put to avoid problem to the users. > Ulises M. Alvarez > > El 16 jul 2024, a la(s) 8:43 a.m., David via Snort-users < > [email protected]> escribió: > > > Hi all, > > I have enabled and configured Snort in PfSense and now I would like to > block the offenders, but I see I need to go rule by rule, for each > category, changing from 'Alert' to 'Drop'. Does anyone know a way to change > this in all at once? > > Thanks. > _______________________________________________ > Snort-users mailing list > [email protected] > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users > > To unsubscribe, send an email to: > [email protected] > > Please visit http://blog.snort.org to stay current on all the latest > Snort news! > > Please follow these rules: > https://snort.org/faq/what-is-the-mailing-list-etiquette > > -- Ulises M. Alvarez https://sophie.unam.mx/ _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
Captura de pantalla 2024-08-02 a la(s) 12.36.15 p.m..png
(image/png, 218.3 KB) - not displayed