• Snort: Alert log format

    logs format
    9
    0 Votes
    9 Posts
    7k Views
    D
    @johnnybee I have the same question. Please share with me if you have the answer. Thanks in advance.
  • Best way to block when behind a proxy

    4
    1
    0 Votes
    4 Posts
    692 Views
    M
    @bmeeks was hoping there was some…trickery. But alas it’s reading the IP header so not much can be done
  • Suricata Alert Log View Filter

    3
    0 Votes
    3 Posts
    317 Views
    NogBadTheBadN
    @bmeeks Thanks Bill.
  • Snort block only inbound traffic

    2
    0 Votes
    2 Posts
    226 Views
    bmeeksB
    The only way to accomplish that would be to rewrite all the rules and reverse the direction logic. That's a lot of work.
  • Snort Custom Rule not alerting on traffic

    snort ids
    5
    0 Votes
    5 Posts
    2k Views
    E
    @bmeeks Ah, that is right. I might have gotten confused with that field. It does work omitting the content section. I appreciate your help!
  • Suricata inline mode with Netgate 6100

    8
    0 Votes
    8 Posts
    2k Views
    bmeeksB
    @pfsjap said in Suricata inline mode with Netgate 6100: Wasn't a driver issue after all. MTU of this interface was 9000 and netmap buffer size (dev.netmap.buf_size) was 2048 (default). After setting buffer size to 9100, Suricata started in inline mode. Found this tunable in here. Ah! Good detective work. The error message certainly was not helpful in this instance. It could have said "out of memory" or "insufficent buffer size" you would think. This error comes from the netmap device code within FreeBSD and has nothing to do with Suricata's use of netmap. Not many folks are using MTU sizes larger than 1500, though.
  • Is Suricata package updates blocked by an internal decision?

    15
    0 Votes
    15 Posts
    3k Views
    DefenderLLCD
    @bmeeks Thank you, Mr. Meeks.
  • Snort vs Suricata Lists

    5
    0 Votes
    5 Posts
    658 Views
    DefenderLLCD
    @Dobby_ Good idea. I do have two 8GB RP4B's just sitting around doing nothing. I was using those for Pi-hole before switching to pfBlockerNG.
  • Blocking p2p on vlan

    5
    0 Votes
    5 Posts
    359 Views
    C
    @the-other I got pfblockerng installed... are there preloaded p2p blocklists or is this something I need to create myself?
  • How to enable IPS - Blocked Offenders is enabled

    7
    2
    0 Votes
    7 Posts
    2k Views
    M
    @bmeeks I meant to update this thread before your response. Beat me to the punch. My misunderstanding is really how to work with the GUI in regards to IPS/IDS. Some of the elements aren't exactly clear so it did require poking through several threads here to understand how the pieces work.
  • how to disable default suricata rules on specific interface

    2
    1
    0 Votes
    2 Posts
    663 Views
    NollipfSenseN
    @jpgpi250 I usually turn off rules here...see arrow in Emerging DNS... [image: 1685541192483-screenshot-2023-05-31-at-8.47.49-am-resized.png]
  • How to implement simple generic auto ban function?

    1
    0 Votes
    1 Posts
    249 Views
    No one has replied
  • [Snort] Possible flaw in ET rules and IPS Policy Security

    8
    0 Votes
    8 Posts
    1k Views
    Dobby_D
    May 27 16:02:49 kernel pid 38637 (snort), jid 0, uid 0, was killed: failed to reclaim memory May 27 16:02:49 kernel pid 38637 (snort), jid 0, uid 0, was killed: failed to reclaim memory Can be pointed to the storage space and/or the amount of ram.
  • 0 Votes
    9 Posts
    2k Views
    S
    @ASGR71 Yes but to be fair 98% of them don’t have any inbound ports forwarding. Some for games or uPnP I suppose. Sine I don’t see I mentioned it above, if one runs Snort or Suricata on WAN, that runs outside the firewall so will block all sorts of things that would get blocked anyway. Running it on LAN avoids a lot of scanning plus will show internal IPs in the alerts.
  • [solved] Suricata Inline Mode with WireGuard interface?

    2
    0 Votes
    2 Posts
    405 Views
    NollipfSenseN
    @Bob-Dig said in Suricata Inline Mode with WireGuard interface?: Is it a good or a bad idea? Interesting question, indeed. One would need a dedicated NIC since one needs Netmap. I was thinking the other day wondering how to assign a NIC to Wireguard...that's how far I got.
  • Is Snort blocking working?

    3
    0 Votes
    3 Posts
    244 Views
    M
    @SteveITS I'm an idiot, was pinging from the wrong firewall! It is indeed blocking. Sorry. I'll delete my post.
  • Can I (how do I) exempt traffic from certainIP's from being scanned

    16
    0 Votes
    16 Posts
    779 Views
    M
    @bmeeks Thanks for this precise description. OK reverted to scanning LAN ;)
  • Snort Inline drop/reject and pass/alert in rules

    1
    0 Votes
    1 Posts
    252 Views
    No one has replied
  • Access from PFSense itself is being blocked by Suricata.

    5
    0 Votes
    5 Posts
    443 Views
    S
    @yet_learningpfsense Also if you’re running Suricata on WAN I’d recommend putting it on LAN. Otherwise it scans outside the firewall so scans all inbound to-be-blocked packets and can only see the NATted IP not LAN devices.
  • snort running to half stop many times a day

    23
    0 Votes
    23 Posts
    3k Views
    B
    @steveits pfsense restart
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.