@justme2 said in Suricata Pass Lists and Alias (URL/URL Table):
Fair enough, sounds good.
Thanks!
I have it working in a new Suricata package for 23.01 and 2.7 CE Devel.
This feature will be in the next update of Suricata that shows up for 23.01 pfSense Plus and 2.7 CE snapshot users. The package version will be 6.0.10_3.
Here are some screenshots showing the new feature in action.
Defined the URL Table alias under FIREWALL > ALIASES > URLs:
Firewall_Alias_URL_Table.png
Assigned the URL Table alias to a custom Pass List on the PASS LISTS tab:
Pass_List_URL_Table_alias.png
Assigned the custom Pass List to the LAN interface in Suricata under INTERFACE SETTINGS:
Custom_Pass_List_assigned.png
Here is the content of the custom Pass List when using View List on the INTERFACE SETTINGS tab for the LAN:
Custom_Pass_List_content.png
And here is the suricata.log startup info for the LAN interface showing the custom blocking plugin read and processed the new "IP_Zoom" table alias:
Interface_suricata_log.png
Looking under DIAGNOSTICS > TABLES shows there are 3525 entries in this URL Table:
Diagnostics_Tables_ip_zoom.png