Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is pfBlocker and Snort compatable?

    Scheduled Pinned Locked Moved pfBlockerNG
    13 Posts 4 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      Velcro
      last edited by

      Newbie question:

      Is pfBlocker compatable with Snort…specifically GeoIP?

      • When I block select countries specifically "TopSpammers", Africa, Asia, South America and North America(except USA and Canada) I get an error message when I update rule set i.e. "Result: Failed", specifically my "Snort OpenAppID Detectors".

      I disable pfBlocker and the rules are updated??

      Any thoughts on how to make these programs coexist? Are there countries I should not block so they coexist?

      Thank you all kindly...

      (I have a few other pfBlocker questions but thought I would address them separately...)

      1 Reply Last reply Reply Quote 0
      • RonpfSR
        RonpfS
        last edited by

        Looks at the Alerts Tab and suppress the IP or the Domain name that is blocked when pfblockerNG is active

        2.4.5-RELEASE-p1 (amd64)
        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

        1 Reply Last reply Reply Quote 0
        • V
          Velcro
          last edited by

          Do I go to the IPv4 tab, hit the "+" sign, create alias and add IP to "IPv4 Lists"?

          Thank you again..

          1 Reply Last reply Reply Quote 0
          • RonpfSR
            RonpfS
            last edited by

            Not the IPV4, the    Firewall / pfBlockerNG / Alerts tab

            2.4.5-RELEASE-p1 (amd64)
            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

            1 Reply Last reply Reply Quote 0
            • V
              Velcro
              last edited by

              I am on the Firewall/pfBlocker/Alerts tab but can't see where I can suppress an IP?

              Is there a setting in pfBlocker(maybe the pfBlocker General tab) that will allow me to suppress an IP for GeoIP?

              Thanks again for the help..

              1 Reply Last reply Reply Quote 0
              • RonpfSR
                RonpfS
                last edited by

                When you see this click on it to get more information about the pfblockerNG functionalities.

                Did you enabled suppression under  Firewall / pfBlockerNG / IP ?

                Alerts can be suppressed using the '+' icon in the Alerts tab and IPs are added to the IPv4 suppression custom list.
                For GeoIP/Blocked IPs in a CIDR other than /32 or /24, will need a 'Whitelist alias' w/ a List Action: 'Permit Outbound' Firewall rule.
                Only 'Deny' type Aliases can be suppressed!

                2.4.5-RELEASE-p1 (amd64)
                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                1 Reply Last reply Reply Quote 0
                • V
                  Velcro
                  last edited by

                  I enabled "Suppression" under Firewall/pfBlockerNG/General…however I do not know where "Firewall / pfBlockerNG / IP"  is...not sure if that is the same?

                  1 Reply Last reply Reply Quote 0
                  • RonpfSR
                    RonpfS
                    last edited by

                    Well there is not suppression setting under Firewall / pfBlockerNG / General in the Development version. It's in the Firewall / pfBlockerNG / IP tab
                    So maybe your tabs are different then mine.  :-[

                    2.4.5-RELEASE-p1 (amd64)
                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                    1 Reply Last reply Reply Quote 0
                    • V
                      Velcro
                      last edited by

                      Seems basic but I cannot find a Firewall/pfblockerng/IP tab? See my screenshots attached.

                      I did find that a pfblockerNGSuppress alias was added however it is currently empty…is that where a suppress IPs go?

                      Might be a different screen to yours and pfBlocker doesn't work with a sg2440 running pfsense 2.3.4?

                      IMG_0145.JPG
                      IMG_0145.JPG_thumb
                      IMG_0144.JPG
                      IMG_0144.JPG_thumb

                      1 Reply Last reply Reply Quote 0
                      • RonpfSR
                        RonpfS
                        last edited by

                        As I stated, I am using a "later/under development" of pfblockerNG, so your tab are quite different from my version.

                        When you can suppress a IP , there is a blue "+" icon on the left of the IP.

                        So in you case, if you want to "Whitelist" the IPs without the "+" icon, you have to follow the instructions:

                        For GeoIP/Blocked IPs in a CIDR other than /32 or /24, will need a 'Whitelist alias' w/ a List Action: 'Permit Outbound' Firewall rule.
                        Only 'Deny' type Aliases can be suppressed!

                        But try to download the rules with a browser https://www.snort.org/downloads/#rule-downloads
                        the IP used on my side is 104.16.63.75

                        Maybe it's the domain name that is blocked.

                        2.4.5-RELEASE-p1 (amd64)
                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                        1 Reply Last reply Reply Quote 0
                        • V
                          Velcro
                          last edited by

                          Thanks RonpfS…I appreciate the help!

                          1 Reply Last reply Reply Quote 0
                          • BBcan177B
                            BBcan177 Moderator
                            last edited by

                            I believe that the Snort OpenAppID Detector Feed is based in South America…

                            "Experience is something you don't get until just after you need it."

                            Website: http://pfBlockerNG.com
                            Twitter: @BBcan177  #pfBlockerNG
                            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                            1 Reply Last reply Reply Quote 0
                            • R
                              Ramosel
                              last edited by

                              @BBcan177:

                              I believe that the Snort OpenAppID Detector Feed is based in South America…

                              Yep, Brazil…    this is the one you helped me with.  I don't use the country lists for that region.

                              TLD blacklist
                              br
                              edu.br

                              TLD whitelist
                              www.ifs.edu.br|200.133.48.21 # for SNORT OpenAppID rule
                              ifs.edu.br|200.133.48.21 # for SNORT OpenAppID rule
                              thor.ifs.edu.br|200.133.48.21 # SNORT OpenAppID rule

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.