Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SNORT blocking friendly IP alias

    Scheduled Pinned Locked Moved IDS/IPS
    7 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Supermule Banned
      last edited by

      Hi Bill

      Just wanna let you know that the friendly IP alias gets blocked in snort desapite having it on the pass list tab.

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        Is the friendly IP alias a static IP, or does it perhaps change now and then?  You can physically verify the actual contents of the Pass List two ways.  First, on the INTERFACE SETTINGS tab for the interface in Suricata, scroll down and click the View List button beside the PASS LIST drop-down.  That will open a pop-up browser window showing the IP addresses in the currently selected list (the one selected in the drop-down).  The other method is to browse via the Diagnostics > Edit File menu to /usr/pbi/suricata-amd64/etc/suricata/ and then down to the specific interface path.  Once there, open up the pass list file.  It will have the same name as what is selected in the drop-down on the INTERFACE SETTINGS tab.

        Another frequent oops committed by users is forgetting to actually assign a PASS LIST to the Suricata interface on the INTERFACE SETTINGS tab.  You select one in the drop-down, then save, and then restart Suricata on the interface.

        Bill

        1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire
          last edited by

          I posted a different thread about Suricata not detecting a WAN VIP in its Home Net, and this caught my eye.  Once I created my own Home Net alias and list, the pass list now starts out:

          10.15.55.1/32
          10.15.55.42/32
          10.15.55.43
          10.99.99.0/24 (the LAN subnet)
          …

          The VIP (10.15.55.43) and anything else I've set on the pass list alias in pfSense show without the "/32"?  May not be an issue but it caught my eye.  We haven't enabled blocking yet so I don't know if it would be blocked, and as I understand it the alerts still show unless blocking is turned on.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          1 Reply Last reply Reply Quote 0
          • S
            Supermule Banned
            last edited by

            Does it make a difference that its Snort that in question??

            @bmeeks:

            Is the friendly IP alias a static IP, or does it perhaps change now and then?  You can physically verify the actual contents of the Pass List two ways.  First, on the INTERFACE SETTINGS tab for the interface in Suricata, scroll down and click the View List button beside the PASS LIST drop-down.  That will open a pop-up browser window showing the IP addresses in the currently selected list (the one selected in the drop-down).  The other method is to browse via the Diagnostics > Edit File menu to /usr/pbi/suricata-amd64/etc/suricata/ and then down to the specific interface path.  Once there, open up the pass list file.  It will have the same name as what is selected in the drop-down on the INTERFACE SETTINGS tab.

            Another frequent oops committed by users is forgetting to actually assign a PASS LIST to the Suricata interface on the INTERFACE SETTINGS tab.  You select one in the drop-down, then save, and then restart Suricata on the interface.

            Bill

            1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire
              last edited by

              @Supermule:

              Does it make a difference that its Snort that in question??

              Well that's what chronic low sleep will do to you. :) Actually I suspect the two packages share a lot of code; for instance the popups for viewing the lists in the Suricata plugin all show "Snort" e.g. "Snort: HOME_NET Viewer."

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              1 Reply Last reply Reply Quote 0
              • bmeeksB
                bmeeks
                last edited by

                @Supermule:

                Does it make a difference that its Snort that in question??

                My bad on giving the Suricata path instead of Snort.  The ideas are the same as the blocking technology is essentially identical in both packages.  In the paths I listed, just replace "suricata" with "snort" and everything else is the same.

                I am mulling over some options for bettering the operation of the PASS LIST (and the automatic default pass list) in both Snort and Suricata.  Might even be able to support aliases at some level, but still thinking that one through for options that won't adversely impact performance.

                Bill

                1 Reply Last reply Reply Quote 0
                • S
                  Supermule Banned
                  last edited by

                  Thanks man! Greatly appreciated!

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.