Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort blocking remote staff when checking email with Outlook

    Scheduled Pinned Locked Moved pfSense Packages
    27 Posts 6 Posters 11.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Cry HavokC
      Cry Havok
      last edited by

      Then how have you told it to suppress the rule? Where did you enter suppress gen_id 137, sig_id 1?

      1 Reply Last reply Reply Quote 0
      • V
        vito
        last edited by

        Under the "suppress" Tab

        I also just tried under adv config. Still not working.

        1 Reply Last reply Reply Quote 0
        • Cry HavokC
          Cry Havok
          last edited by

          What version of pfSense and the Snort package are you running?

          1 Reply Last reply Reply Quote 0
          • V
            vito
            last edited by

            PF 2.0 release
            Snort 2.9.0.5 pkg v. 2.0

            1 Reply Last reply Reply Quote 0
            • Cry HavokC
              Cry Havok
              last edited by

              Checking what is added to the snort config, it looks like the suppress tab doesn't work. Only items added to the Advanced tab are added to the config file from what I can see.

              1 Reply Last reply Reply Quote 0
              • V
                vito
                last edited by

                Thanks for the reply and testing Cry Havok

                OP and other users that posted to the thread.
                Can you post your versions of Snort and PF?
                Also note where you have the suppress line added.

                If this is a bug, it will help with trouble shooting.

                1 Reply Last reply Reply Quote 0
                • swinnS
                  swinn
                  last edited by

                  @Cry:

                  Checking what is added to the snort config, it looks like the suppress tab doesn't work. Only items added to the Advanced tab are added to the config file from what I can see.

                  Did you also set the suppression rule list you created to the interface (If Settings->Suppression and Filtering)? If the interface is still set to default then it will not suppress any alerts.

                  1 Reply Last reply Reply Quote 0
                  • Cry HavokC
                    Cry Havok
                    last edited by

                    @swinn:

                    Did you also set the suppression rule list you created to the interface (If Settings->Suppression and Filtering)? If the interface is still set to default then it will not suppress any alerts.

                    No - didn't know that those extra steps were required.

                    1 Reply Last reply Reply Quote 0
                    • V
                      vito
                      last edited by

                      When deleting the line from Adv config, the system enter this in the gui field and reverted my config.
                      ²êi­ë,éâw]û²("w
                      Yes, that is correct, it was just a bunch of garbage.
                      To be sure, i tried different browsers (FF,Chrome)

                      1 Reply Last reply Reply Quote 0
                      • D
                        djmime
                        last edited by

                        after adding the suppress to the interface snort stop blocking my OMA or OWA
                        thanks for the tip
                        :)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.