Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort problem

    Scheduled Pinned Locked Moved pfSense Packages
    17 Posts 6 Posters 7.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      darklogic
      last edited by

      Here is my suggestion. I would recommend backing up your config and reinstalling 1.2.3 Release. I had to do this because of some odd issues with the upgrades from 1.2.3RC I realize you went from 1.2.2, but maybe the same issue with the hanging.

      I have noticed the same thing with the block page after restarting the system or the snort service where everything will clear. I noticed this after upgrading to the latest snort package 2.8.6 pkg v. 1.27, I am not sure what that is about, but I have had that happen to me as well on more than one occasion. Make sure you don't clear your alert list, That will mess with the blocked IP's.

      As far as going longer than 1 hour. I would recomend maybe up to 24 hr's.

      Also note there are some known issues with the snort package and whitelisting of IP's.

      1 Reply Last reply Reply Quote 0
      • A
        alanon
        last edited by

        It took a while but the IP's started showing up again.  Unfortunately I can't rebuild, after all the downtime the last few days we have to try and get things working as is.  I hate having to test all this in a live environment but its our only choice right now.

        After whitelisting him he still could not get through, couldn't hit the web site or SSH through.  If the whitelisting doesn't work I may have to scale back the categories, so that we at least have some protection.  I had to disable snort so he could work, he's one of the main developers.

        I wish I could add the alias' we have to the whitelist (if it worked).  We have a monitoring company that performs many checks, all started to fail after enabling snort.

        1 Reply Last reply Reply Quote 0
        • D
          darklogic
          last edited by

          Oh one other thing. You might want to look into the Country Block and IP Block feature package. Also install cron package to use hand and hand with Country Block. the US has around 1.5 billion active IP and the rest our reserved or in other Countries. I block everything from our network other than the US based IP's. Something to consider. Cut the head of the snake off if these attacks are coming from somewhere other than the US.

          Matt

          1 Reply Last reply Reply Quote 0
          • D
            darklogic
            last edited by

            Don't Block United Kingdom or Canada if you use BlackBerry Service LOL.

            Matt

            1 Reply Last reply Reply Quote 0
            • A
              alanon
              last edited by

              I wish I could, we are a website with global users (top 10K of the Internet).  We have clients that connect to our database through an API all over the world.

              I am suprised this is our first DDOS.

              I was going to add their (clients) IP's to the whitelist, but if it's not reliable not sure if it would matter… I think we just have to do a lot of tweaking to get things working.

              1 Reply Last reply Reply Quote 0
              • D
                darklogic
                last edited by

                Without to much detail, what kinds of service are you hosting and are you using pfsense for VPN use? Have you considered placing another system in front of the pfsense box. I hate to do this on the pfsense forms, but I am trying to help one being out. ClearOS or Untangle. Untangle uses SNORT and has it's own designed system called attack blocker which is seperate from the snort package. You can run it in transparent mode in front of or behind an exisitng firewall. So if you have some free public IP's availible, you could run it in transparent mode in front of your pfsense box until this gets under control. This is only if you cannot get SNORT to work properly.

                Matt

                1 Reply Last reply Reply Quote 0
                • A
                  alanon
                  last edited by

                  The easiest way to put it, is we deliver a large amount of data, our database grows by around 500GB/month.  We are a search engine. Our developers, many overseas, come in through VPN.  I have whitelist VPN selected, but it didn't seem to help.

                  We've had to disable snort and reboot the firewall to get things somewhat back to normal.

                  We are going to see if we can find someone (expert) who can help, this is beyond our normal scope.  We were hoping a quick install and a couple check boxes would stop, or deter, the DDOS.

                  Thanks

                  1 Reply Last reply Reply Quote 0
                  • J
                    jamesdean
                    last edited by

                    @alanon

                    Check you PM. I believe I can help you.

                    James

                    1 Reply Last reply Reply Quote 0
                    • A
                      alanon
                      last edited by

                      Thanks, just sent you a message.

                      1 Reply Last reply Reply Quote 0
                      • D
                        dolphin46
                        last edited by

                        global setting
                              don not install -checked
                        rules
                              update rules

                        1 Reply Last reply Reply Quote 0
                        • ?
                          A Former User
                          last edited by

                          When is the package going to be fixed ? I am using a another flavor of firewall and it has dns problems .

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.