Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata Ignoring IPs in Pass List Aliases (Yes I've Restarted)

    Scheduled Pinned Locked Moved IDS/IPS
    14 Posts 8 Posters 5.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      abujammy
      last edited by

      @doktornotor thank you SO MUCH!  This is the part that I was missing!!

      @bmeeks I read the notes on the pass list screen like 12 times so a note there that it needs to be enabled on each interface would have definitely helped.

      So that leads me to one more smaller question, now that I know that I can only have one pass list per interface, I have my alias lists all neat and organized into groups, so therefore I want multiple alias lists to be applied as pass lists to a given interface.  Otherwise I either have to unorganize my aliases or duplicate them in one big "master" pass list alias list.  Is there a third option that I'm unaware of?  Is there a way to pull multiple lists together via a URL that pfSense provides for each alias like I can do with pfBlocker's blocklists?

      1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire
        last edited by

        @abujammy:

        I want multiple alias lists to be applied as pass lists to a given interface.  Otherwise I either have to unorganize my aliases or duplicate them in one big "master" pass list alias list.

        A firewall alias can contain other aliases…on the Firewall: Aliases page it says, "You can enter the name of an alias instead of the host, network or port in all fields that have a red background."

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • A
          abujammy
          last edited by

          @teamits I completely missed that.  That totally solves my problem.  Thank you as well.  I'm loving this community so far.  :D

          1 Reply Last reply Reply Quote 0
          • B
            bera
            last edited by

            hi guys…

            i recently update my pfsense to version 2.3-release as per snapshot attached...

            apparently suricata do detect the alias i declare under firewall > alias > ip menu...

            but only the "defaults" are available in the suricata > interfaces > wan settings > Networks Suricata Should Inspect and Protect drop down menu even though i already declare it in the pass list menu ...

            please advise and thank you in advance

            1 Reply Last reply Reply Quote 0
            • N
              ntct
              last edited by

              +1

              I use suricata 3.0_5

              Pass Lists created on the PASS LIST tab are not available in the drop-down for selection on the INTERFACE tab for a Suricata instance.

              1 Reply Last reply Reply Quote 0
              • bmeeksB
                bmeeks
                last edited by

                @ntct:

                +1

                I use suricata 3.0_5

                Pass Lists created on the PASS LIST tab are not available in the drop-down for selection on the INTERFACE tab for a Suricata instance.

                I had not noticed this.  I will investigate.  Thanks for the report.

                Bill

                1 Reply Last reply Reply Quote 0
                • P
                  pfsenseboonie
                  last edited by

                  @bmeeks:

                  @ntct:

                  +1

                  I use suricata 3.0_5

                  Pass Lists created on the PASS LIST tab are not available in the drop-down for selection on the INTERFACE tab for a Suricata instance.

                  I had not noticed this.  I will investigate.  Thanks for the report.

                  Bill

                  I second this.  Just upgraded to 2.3 and it has suricata 3.0_5 the passlist are not selectable from the dropdowns in the interface.

                  1 Reply Last reply Reply Quote 0
                  • T
                    tehknowledge
                    last edited by

                    +1 this issue as well. Just upgraded to 2.3 and Suricata will not allow me to use the custom alias for home net. I do not see a passlist anymore. ???

                    1 Reply Last reply Reply Quote 0
                    • bmeeksB
                      bmeeks
                      last edited by

                      @tehknowledge:

                      +1 this issue as well. Just upgraded to 2.3 and Suricata will not allow me to use the custom alias for home net. I do not see a passlist anymore. ???

                      There is a typo in the Bootstrap conversion code for Suricata.  Actually the Snort version of a variable got pasted in there by yours truly without him realizing it.  I found the bug and fixed it today in the version I will be posting very soon (hopefully on Thursday US Eastern time).  I have one more issue I'm working on, then the pull request will be ready.

                      Bill

                      1 Reply Last reply Reply Quote 0
                      • B
                        bera
                        last edited by

                        awesome…

                        i thought my configuration went south after the upgrade...  :o :o :o

                        keep up the good work....

                        many thanks...

                        1 Reply Last reply Reply Quote 0
                        • T
                          tehknowledge
                          last edited by

                          You rock Bill. Thank you!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.