Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    how to disable default suricata rules on specific interface

    Scheduled Pinned Locked Moved IDS/IPS
    2 Posts 2 Posters 550 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jpgpi250J
      jpgpi250
      last edited by jpgpi250

      running suricata 6.0.4_1 (highest available on pfsense 2.6.0)
      don't want to install pfsense 2.7.0, it still has 63 open bugs, according to the roadmap - looks like the number of bugs is increasing, checking daily)

      I have WAN + multiple LAN adapters on my system, so my rules are applied on WAN.

      I need to apply custom rules on a specific LAN adapter, so I added the interface and unchecked all rules in "DNS categories", including flow bits.

      When I check the rules (active rules) on the LAN interface, my custom rules are listed, but also a bunch of rules I don't want / need on this interface, all with the message "SURICATA ..."

      I've tried to create a "SID Mgmt" file (disablesid-DNS.conf), content:

      # disable suricata default rules for this interface (DNS)
      1:2200000-2299999
      

      and applied it.
      526253e0-929f-49f6-b57b-be5370faa3e6-image.png

      I checked the rebuild checkbox and saved.

      Unfortunately, the rules are still listed in the active rules.

      Is it possible to remove these rules, only for that interface (must remain active on the WAN interface)?

      Thanks for your time and effort.

      NollipfSenseN 1 Reply Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense @jpgpi250
        last edited by

        @jpgpi250 I usually turn off rules here...see arrow in Emerging DNS...

        Screenshot 2023-05-31 at 8.47.49 AM.png

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        1 Reply Last reply Reply Quote 0
        • jpgpi250J jpgpi250 referenced this topic on
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.