Re: Doubt with Snort and PfSense

"Russ Combs \(rucombs\) via Snort-users" <[email protected]> Mon, 5 Aug 2024 16:26:08 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <MN2PR11MB40483D4CD48B4CE583A878D9B7BE2@MN2PR11MB4048.namprd11.prod.outlook.com>
There is a way to do it via Snort 3 configuration, not sure about on PfSense.

$ snort --help-config ips | grep action
string ips.action_map[].replace: action you want to change
string ips.action_map[].with: action you want to use instead
string ips.action_override: use this action for all rules (applied before action_map)

So if you just set ips.action_override = 'block' that will get what you want.

The action_map offers other possibilities.
________________________________
From: Snort-users <[email protected]> on behalf of David via Snort-users <[email protected]>
Sent: Friday, August 2, 2024 1:40 PM
To: Sreedhar Reddy (mopreddy) via Snort-users <[email protected]>; Ulises Mora Alvarez <[email protected]>
Subject: Re: [Snort-users] Doubt with Snort and PfSense


Hello,

sorry for writting again, but nobody has helped me yet.

Is there any way to update all the rules at once so they are in block mode instead of in alert mode?

Thanks.
David


-------- Mensaje original --------
El 18/7/24 19:33, David via Snort-users ha escrito:

Hello,

I already had checked those resources but in none of them I saw how to change in all the rules from alert to drop action, something needed as far as I understand to really block even if it is working in blocking mode; I mean, if I enable blocking mode but the rules are in alert action, no block will happen at the end.

Also, note that I am not starting with blocking, I have been working with alerts for months to ensure the behaviour.

Thanks!


-------- Mensaje original --------
El 16/7/24 17:52, Ulises Mora Alvarez ha escrito:
Hello.
This is not the case, I suggest you read the Netgate guide.
<https://docs.netgate.com/pfsense/packages/snort/setup.html>
docs.netgate.com<https://docs.netgate.com/pfsense/packages/snort/setup.html>
[X]<https://docs.netgate.com/pfsense/packages/snort/setup.html>

I also suggest a look at this video....
<https://youtu.be/2q_g9GgkvWA>
youtu.be<https://youtu.be/2q_g9GgkvWA>
[X]<https://youtu.be/2q_g9GgkvWA>

In my experience, when using an IDS/IPS, like Snort, the tricky thing is not to start blocking, but to set which alerts should be suppressed and which exceptions to put to avoid problem to the users.
Ulises M. Alvarez

El 16 jul 2024, a la(s) 8:43 a.m., David via Snort-users <[email protected]> escribió:


Hi all,

I have enabled and configured Snort in PfSense and now I would like to block the offenders, but I see I need to go rule by rule, for each category, changing from 'Alert' to 'Drop'. Does anyone know a way to change this in all at once?

Thanks.
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

   To unsubscribe, send an email to:
   [email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette