Re: Doubt with Snort and PfSense

David via Snort-users <[email protected]> Fri, 02 Aug 2024 18:57:31 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Hello Ulises, all,

thank you very much for the tip, but I already have it enabled, as shown below:

[image.png]

However, when I see the rules for the selected Snort interface, I see the rules as 'alert' instead of 'blocking'. I can change them manually, but one by one...

[image.png]

Am I missing something?

Thanks!

Regards,
David

On Friday, 2 August 2024 at 20:46, Ulises Mora Alvarez <[email protected]> wrote:

> Hi,
>
> Hello,
> Yes, it is possible in the menu
> Snort Interfaces > Edit > Interface settings
>
> Once the blocking option is enabled, all alerts will generate blocking of the IPs that generated the alerts.
>
> [Captura de pantalla 2024-08-02 a la(s) 12.36.15 p.m..png]
>
> El vie, 2 ago 2024 a la(s) 11:40 a.m., <[email protected]> escribió:
>
>> Hello,
>>
>> sorry for writting again, but nobody has helped me yet.
>>
>> Is there any way to update all the rules at once so they are in block mode instead of in alert mode?
>>
>> Thanks.
>> David
>>
>> -------- Mensaje original --------
>> El 18/7/24 19:33, David via Snort-users  ha escrito:
>>
>>> Hello,
>>>
>>> I already had checked those resources but in none of them I saw how to change in all the rules from alert to drop action, something needed as far as I understand to really block even if it is working in blocking mode; I mean, if I enable blocking mode but the rules are in alert action, no block will happen at the end.
>>>
>>> Also, note that I am not starting with blocking, I have been working with alerts for months to ensure the behaviour.
>>>
>>> Thanks!
>>>
>>> -------- Mensaje original --------
>>> El 16/7/24 17:52, Ulises Mora Alvarez  ha escrito:
>>>
>>>> Hello.
>>>> This is not the case, I suggest you read the Netgate guide.
>>>> https://docs.netgate.com/pfsense/packages/snort/setup.html
>>>>
>>>> [docs.netgate.com](https://docs.netgate.com/pfsense/packages/snort/setup.html)	https://docs.netgate.com/pfsense/packages/snort/setup.html
>>>>
>>>> I also suggest a look at this video....
>>>> https://youtu.be/2q_g9GgkvWA
>>>>
>>>> [youtu.be](https://youtu.be/2q_g9GgkvWA)	https://youtu.be/2q_g9GgkvWA
>>>>
>>>> In my experience, when using an IDS/IPS, like Snort, the tricky thing is not to start blocking, but to set which alerts should be suppressed and which exceptions to put to avoid problem to the users.
>>>> Ulises M. Alvarez
>>>>
>>>>> El 16 jul 2024, a la(s) 8:43 a.m., David via Snort-users <[email protected]> escribió:
>>>>
>>>>> 
>>>>> Hi all,
>>>>>
>>>>> I have enabled and configured Snort in PfSense and now I would like to block the offenders, but I see I need to go rule by rule, for each category, changing from 'Alert' to 'Drop'. Does anyone know a way to change this in all at once?
>>>>>
>>>>> Thanks.
>>>>>
>>>>> _______________________________________________
>>>>> Snort-users mailing list
>>>>> [email protected]
>>>>> Go to this URL to change user options or unsubscribe:
>>>>> https://lists.snort.org/mailman/listinfo/snort-users
>>>>>
>>>>> To unsubscribe, send an email to:
>>>>> [email protected]
>>>>>
>>>>> Please visit http://blog.snort.org to stay current on all the latest Snort news!
>>>>>
>>>>> Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
>
> --
>
> Ulises M. Alvarez
> https://sophie.unam.mx/

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette