Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata 6.0.3_3 pass list missing all single IPs (alias, DNS)

    Scheduled Pinned Locked Moved IDS/IPS
    13 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SteveITS Galactic Empire @SteveITS
      last edited by SteveITS

      @bmeeks If I change the alias to be type Network(s) and set OurIP/32, it immediately shows under View List. It was type Host(s).

      Edit: pfSense lets me enter the ITS_Office alias there, but doesn't autocomplete it...it is autocompleting only the networks alias. Makes sense, just noting it. Have to enter IP/32 and have two places to change it.

      Edit 2: Note the ITSMailGuard alias was type Network(s), which is consistent with that working.

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote πŸ‘ helpful posts!

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @SteveITS
        last edited by SteveITS

        I pulled up routers using 21.05 and 2.5.2 with Suricata 6.0.0_14 which has the Suricata_Trusted_Hosts alias set to Hosts(s) and working for IPs there.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote πŸ‘ helpful posts!

        S 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @SteveITS
          last edited by

          I pulled up a 21.05 with Snort 4.1.4_3 and it is OK with IPs.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote πŸ‘ helpful posts!

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks
            last edited by

            I suspect it is somehow related to the bugfix I linked, but I can't say with absolute certainty. I did not author that particular code fix. It was done by a Netgate staff developer. It's also possible, but not as likely, that something in pfSense 21.05.1 with respect to alias resolution changed.

            S 2 Replies Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @bmeeks
              last edited by

              @bmeeks said in Suricata pass list missing some IPs:

              possible, but not as likely, that something in pfSense 21.05.1 with respect to alias resolution changed.

              Using just one IP didn’t work so that’s not related to an alias.

              I can try upgrading other Suricata installs maybe tonight or tomorrow night but it should be easy to replicate if someone can:

              • create alias, type Host
              • add one ip to alias
              • apply alias change
                (- assign alias to pass list and restart Suricata)
              • click View List

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote πŸ‘ helpful posts!

              1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @bmeeks
                last edited by

                @bmeeks I duplicated the behavior this morning on our internal 2.5.2 router simply by upgrading pfSense-pkg-suricata from 6.0.0_14 to 6.0.3_3. Notably it omits DNS, gateway, etc. ... anything that is configured or detected as an IP and not a /32. Changing aliases one at a time from Host(s) to Network(s) adds each to the pass list.

                https://redmine.pfsense.org/issues/12476

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote πŸ‘ helpful posts!

                bmeeksB 1 Reply Last reply Reply Quote 0
                • bmeeksB
                  bmeeks @SteveITS
                  last edited by

                  @steveits said in Suricata pass list missing some IPs:

                  @bmeeks I duplicated the behavior this morning on our internal 2.5.2 router simply by upgrading pfSense-pkg-suricata from 6.0.0_14 to 6.0.3_3. Notably it omits DNS, gateway, etc. ... anything that is configured or detected as an IP and not a /32. Changing aliases one at a time from Host(s) to Network(s) adds each to the pass list.

                  https://redmine.pfsense.org/issues/12476

                  I will take a look at this. I'm still guessing it is an unintended consequence of fixing an earlier bug where some aliases resulted in an empty array() variable getting written to the HOME_NET variable.

                  1 Reply Last reply Reply Quote 1
                  • bmeeksB
                    bmeeks
                    last edited by

                    The Netgate developer team beat me fixing this bug. A pull request to address this problem has been posted here: https://github.com/pfsense/FreeBSD-ports/pull/1117. Look for the fix to get merged into the production package in the near future.

                    In the meantime, if you can read and understand GitHub diff files, you can make the simple edit yourself on your firewalls.

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      SteveITS Galactic Empire @bmeeks
                      last edited by SteveITS

                      Thank you both. Seems good to me, changed the aliases back and the list looks like my original.

                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                      Upvote πŸ‘ helpful posts!

                      1 Reply Last reply Reply Quote 0
                      • bmeeksB
                        bmeeks
                        last edited by

                        Great! The change should make it into a formal package update soon.

                        Thanks to @viktor_g for the quick fix. He knew right where to look. It would have taken me a bit longer to dig around in the function code and find the issue.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.