Suricata 7.0.8_3 IPS Mode Not Blocking on pfSense 2.8.1
-
pfSense Version: 2.8.1-RELEASE
Suricata Package Version: 7.0.8_3
System: VMware Virtual Machine with vmxnet3 NICs.
Summary of Issue:
I have configured Suricata for IPS blocking ('Block Offenders' is enabled). The system generates alerts correctly, but fails to block any traffic. The configuration appears correct, but the blocking action does not occur.
Key Troubleshooting Finding:
Blocking fails in both Inline IPS Mode (with Workers Run Mode) and also in Legacy IPS Mode. In all tested configurations, the correct alert is generated in the Suricata log, but the traffic is allowed to pass through.
-
@kkierii In inline mode you need to set up the rules for blocking.
For legacy, is one of the IPs in a pass list? The blocks should occur but expire in 15 minutes by default.
-
@SteveITS Pass lists are completely blank. there are some blocks that have occured so it seems to be blocking some things.