• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Have a question on SIB Management Drop SID List

IDS/IPS
3
6
163
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    stanwij1
    last edited by Jan 22, 2025, 4:12 PM

    trying to use DROP list in SID mgmt but can't choose Drop SID List under Interface SID Management List Assignments. It Says N/A? How can I change that to choose LAN Drops list?
    🔒 Log in to view

    S 1 Reply Last reply Jan 22, 2025, 4:27 PM Reply Quote 0
    • S
      SteveITS Galactic Empire @stanwij1
      last edited by Jan 22, 2025, 4:27 PM

      @stanwij1 I want to say that's only when using Inline mode.

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      S 1 Reply Last reply Jan 22, 2025, 4:29 PM Reply Quote 0
      • S
        stanwij1 @SteveITS
        last edited by Jan 22, 2025, 4:29 PM

        @SteveITS oh so I am running Legacy mode, so you can't do this under legacy mode?

        B 1 Reply Last reply Jan 22, 2025, 5:05 PM Reply Quote 0
        • B
          bmeeks @stanwij1
          last edited by bmeeks Jan 22, 2025, 5:06 PM Jan 22, 2025, 5:05 PM

          @stanwij1 said in Have a question on SIB Management Drop SID List:

          @SteveITS oh so I am running Legacy mode, so you can't do this under legacy mode?

          You can only use a Drop SID List when Inline IPS Mode is enabled in Snort. Legacy Blocking Mode does not support changing individual rules to BLOCK as the internal plumbing of the Snort.

          If you are using Suricata (it's not clear from your post which IDS/IPS package you are referring to), then you can enable a special option under the Blocking section of the INTERFACE SETTINGS tab that will let you emulate a sort of IPS mode by individually setting rules to DROP and traffic will only be blocked when those rules trigger. As I recall, that option is called "Block on DROP Only" and is a checkbox.

          S 1 Reply Last reply Jan 22, 2025, 5:09 PM Reply Quote 0
          • S
            stanwij1 @bmeeks
            last edited by Jan 22, 2025, 5:09 PM

            @bmeeks thanks for your response, yes using Suricata. Issue is, using legacy mode, I went into individual interface rules, and clicked the Action and changed to Drop, but it isn't dropping, still showing in alerts, is that because need to check the box to Block on Drop?

            B 1 Reply Last reply Jan 22, 2025, 5:11 PM Reply Quote 0
            • B
              bmeeks @stanwij1
              last edited by bmeeks Jan 22, 2025, 5:11 PM Jan 22, 2025, 5:11 PM

              @stanwij1 said in Have a question on SIB Management Drop SID List:

              @bmeeks thanks for your response, yes using Suricata. Issue is, using legacy mode, I went into individual interface rules, and clicked the Action and changed to Drop, but it isn't dropping, still showing in alerts, is that because need to check the box to Block on Drop?

              Yes, you must check the box on the INTERFACE SETTINGS tab to enable "Block on DROP Only". That is a config logic flag the code checks in other places so it knows what options to offer the user in the GUI.

              1 Reply Last reply Reply Quote 0
              5 out of 6
              • First post
                5/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.