Re: Doubt with Snort and PfSense

Ulises Mora Alvarez via Snort-users <[email protected]> Fri, 2 Aug 2024 13:20:16 -0600
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CANpcZR6ovTpF-8yAu6_UZOLV+JEEzdBVB-JdqCLpvR14PZd9Cw@mail.gmail.com>
I think you are all set...
From your screenshots I've noticed you are in "Inline IPS Mode," and
there's one note on pfSense about blocked IPs on such mode:

Note: Only blocked IP addresses from Legacy Mode interfaces are shown! For
inline IPS mode interfaces, dropped IP addresses are highlighted on the
ALERTS tab.

Are you viewing highlighted lines on the Alerts tab?

El vie, 2 ago 2024 a la(s) 12:57 p.m., <[email protected]>
escribió:

> Hello Ulises, all,
>
> thank you very much for the tip, but I already have it enabled, as shown
> below:
>
> [image: image.png]
>
> However, when I see the rules for the selected Snort interface, I see the
> rules as 'alert' instead of 'blocking'. I can change them manually, but one
> by one...
>
> [image: image.png]
>
>
> Am I missing something?
>
> Thanks!
>
> Regards,
> David
>
>
> On Friday, 2 August 2024 at 20:46, Ulises Mora Alvarez <
> [email protected]> wrote:
>
> Hi,
>
> Hello,
> Yes, it is possible in the menu
> Snort Interfaces > Edit > Interface settings
>
> Once the blocking option is enabled, all alerts will generate blocking of
> the IPs that generated the alerts.
>
>
> [image: Captura de pantalla 2024-08-02 a la(s) 12.36.15 p.m..png]
>
>
> El vie, 2 ago 2024 a la(s) 11:40 a.m., <[email protected]>
> escribió:
>
>> Hello,
>>
>> sorry for writting again, but nobody has helped me yet.
>>
>> Is there any way to update all the rules at once so they are in block
>> mode instead of in alert mode?
>>
>> Thanks.
>> David
>>
>>
>> -------- Mensaje original --------
>> El 18/7/24 19:33, David via Snort-users ha escrito:
>>
>> Hello,
>>
>> I already had checked those resources but in none of them I saw how to
>> change in all the rules from alert to drop action, something needed as far
>> as I understand to really block even if it is working in blocking mode; I
>> mean, if I enable blocking mode but the rules are in alert action, no block
>> will happen at the end.
>>
>> Also, note that I am not starting with blocking, I have been working with
>> alerts for months to ensure the behaviour.
>>
>> Thanks!
>>
>>
>> -------- Mensaje original --------
>> El 16/7/24 17:52, Ulises Mora Alvarez ha escrito:
>>
>> Hello.
>> This is not the case, I suggest you read the Netgate guide.
>> docs.netgate.com
>> <https://docs.netgate.com/pfsense/packages/snort/setup.html>
>> <https://docs.netgate.com/pfsense/packages/snort/setup.html>
>> <https://docs.netgate.com/pfsense/packages/snort/setup.html>
>>
>> I also suggest a look at this video....
>> youtu.be <https://youtu.be/2q_g9GgkvWA>
>> <https://youtu.be/2q_g9GgkvWA> <https://youtu.be/2q_g9GgkvWA>
>>
>> In my experience, when using an IDS/IPS, like Snort, the tricky thing is
>> not to start blocking, but to set which alerts should be suppressed and
>> which exceptions to put to avoid problem to the users.
>> Ulises M. Alvarez
>>
>> El 16 jul 2024, a la(s) 8:43 a.m., David via Snort-users <
>> [email protected]> escribió:
>>
>> 
>> Hi all,
>>
>> I have enabled and configured Snort in PfSense and now I would like to
>> block the offenders, but I see I need to go rule by rule, for each
>> category, changing from 'Alert' to 'Drop'. Does anyone know a way to change
>> this in all at once?
>>
>> Thanks.
>> _______________________________________________
>> Snort-users mailing list
>> [email protected]
>> Go to this URL to change user options or unsubscribe:
>> https://lists.snort.org/mailman/listinfo/snort-users
>>
>> To unsubscribe, send an email to:
>> [email protected]
>>
>> Please visit http://blog.snort.org to stay current on all the latest
>> Snort news!
>>
>> Please follow these rules:
>> https://snort.org/faq/what-is-the-mailing-list-etiquette
>>
>>
>
> --
> Ulises M. Alvarez
> https://sophie.unam.mx/
>
>
>

-- 
Ulises M. Alvarez
https://sophie.unam.mx/

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
Captura de pantalla 2024-08-02 a la(s) 12.36.15 p.m..png (image/png, 218.3 KB) - not displayed
image.png (image/png, 111.4 KB) - not displayed
image.png (image/png, 150.5 KB) - not displayed