Re: Doubt with Snort and PfSense
David via Snort-users <[email protected]> Fri, 02 Aug 2024 18:57:31 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Hello Ulises, all, thank you very much for the tip, but I already have it enabled, as shown below: [image.png] However, when I see the rules for the selected Snort interface, I see the rules as 'alert' instead of 'blocking'. I can change them manually, but one by one... [image.png] Am I missing something? Thanks! Regards, David On Friday, 2 August 2024 at 20:46, Ulises Mora Alvarez <[email protected]> wrote: > Hi, > > Hello, > Yes, it is possible in the menu > Snort Interfaces > Edit > Interface settings > > Once the blocking option is enabled, all alerts will generate blocking of the IPs that generated the alerts. > > [Captura de pantalla 2024-08-02 a la(s) 12.36.15 p.m..png] > > El vie, 2 ago 2024 a la(s) 11:40 a.m., <[email protected]> escribió: > >> Hello, >> >> sorry for writting again, but nobody has helped me yet. >> >> Is there any way to update all the rules at once so they are in block mode instead of in alert mode? >> >> Thanks. >> David >> >> -------- Mensaje original -------- >> El 18/7/24 19:33, David via Snort-users ha escrito: >> >>> Hello, >>> >>> I already had checked those resources but in none of them I saw how to change in all the rules from alert to drop action, something needed as far as I understand to really block even if it is working in blocking mode; I mean, if I enable blocking mode but the rules are in alert action, no block will happen at the end. >>> >>> Also, note that I am not starting with blocking, I have been working with alerts for months to ensure the behaviour. >>> >>> Thanks! >>> >>> -------- Mensaje original -------- >>> El 16/7/24 17:52, Ulises Mora Alvarez ha escrito: >>> >>>> Hello. >>>> This is not the case, I suggest you read the Netgate guide. >>>> https://docs.netgate.com/pfsense/packages/snort/setup.html >>>> >>>> [docs.netgate.com](https://docs.netgate.com/pfsense/packages/snort/setup.html) https://docs.netgate.com/pfsense/packages/snort/setup.html >>>> >>>> I also suggest a look at this video.... >>>> https://youtu.be/2q_g9GgkvWA >>>> >>>> [youtu.be](https://youtu.be/2q_g9GgkvWA) https://youtu.be/2q_g9GgkvWA >>>> >>>> In my experience, when using an IDS/IPS, like Snort, the tricky thing is not to start blocking, but to set which alerts should be suppressed and which exceptions to put to avoid problem to the users. >>>> Ulises M. Alvarez >>>> >>>>> El 16 jul 2024, a la(s) 8:43 a.m., David via Snort-users <[email protected]> escribió: >>>> >>>>> >>>>> Hi all, >>>>> >>>>> I have enabled and configured Snort in PfSense and now I would like to block the offenders, but I see I need to go rule by rule, for each category, changing from 'Alert' to 'Drop'. Does anyone know a way to change this in all at once? >>>>> >>>>> Thanks. >>>>> >>>>> _______________________________________________ >>>>> Snort-users mailing list >>>>> [email protected] >>>>> Go to this URL to change user options or unsubscribe: >>>>> https://lists.snort.org/mailman/listinfo/snort-users >>>>> >>>>> To unsubscribe, send an email to: >>>>> [email protected] >>>>> >>>>> Please visit http://blog.snort.org to stay current on all the latest Snort news! >>>>> >>>>> Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette > > -- > > Ulises M. Alvarez > https://sophie.unam.mx/ _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette