Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata Ignoring IPs in Pass List Aliases (Yes I've Restarted)

    Scheduled Pinned Locked Moved IDS/IPS
    14 Posts 8 Posters 5.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SteveITS Galactic Empire
      last edited by

      @abujammy:

      I want multiple alias lists to be applied as pass lists to a given interface.  Otherwise I either have to unorganize my aliases or duplicate them in one big "master" pass list alias list.

      A firewall alias can contain other aliases…on the Firewall: Aliases page it says, "You can enter the name of an alias instead of the host, network or port in all fields that have a red background."

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      1 Reply Last reply Reply Quote 0
      • A
        abujammy
        last edited by

        @teamits I completely missed that.  That totally solves my problem.  Thank you as well.  I'm loving this community so far.  :D

        1 Reply Last reply Reply Quote 0
        • B
          bera
          last edited by

          hi guys…

          i recently update my pfsense to version 2.3-release as per snapshot attached...

          apparently suricata do detect the alias i declare under firewall > alias > ip menu...

          but only the "defaults" are available in the suricata > interfaces > wan settings > Networks Suricata Should Inspect and Protect drop down menu even though i already declare it in the pass list menu ...

          please advise and thank you in advance

          1 Reply Last reply Reply Quote 0
          • N
            ntct
            last edited by

            +1

            I use suricata 3.0_5

            Pass Lists created on the PASS LIST tab are not available in the drop-down for selection on the INTERFACE tab for a Suricata instance.

            1 Reply Last reply Reply Quote 0
            • bmeeksB
              bmeeks
              last edited by

              @ntct:

              +1

              I use suricata 3.0_5

              Pass Lists created on the PASS LIST tab are not available in the drop-down for selection on the INTERFACE tab for a Suricata instance.

              I had not noticed this.  I will investigate.  Thanks for the report.

              Bill

              1 Reply Last reply Reply Quote 0
              • P
                pfsenseboonie
                last edited by

                @bmeeks:

                @ntct:

                +1

                I use suricata 3.0_5

                Pass Lists created on the PASS LIST tab are not available in the drop-down for selection on the INTERFACE tab for a Suricata instance.

                I had not noticed this.  I will investigate.  Thanks for the report.

                Bill

                I second this.  Just upgraded to 2.3 and it has suricata 3.0_5 the passlist are not selectable from the dropdowns in the interface.

                1 Reply Last reply Reply Quote 0
                • T
                  tehknowledge
                  last edited by

                  +1 this issue as well. Just upgraded to 2.3 and Suricata will not allow me to use the custom alias for home net. I do not see a passlist anymore. ???

                  1 Reply Last reply Reply Quote 0
                  • bmeeksB
                    bmeeks
                    last edited by

                    @tehknowledge:

                    +1 this issue as well. Just upgraded to 2.3 and Suricata will not allow me to use the custom alias for home net. I do not see a passlist anymore. ???

                    There is a typo in the Bootstrap conversion code for Suricata.  Actually the Snort version of a variable got pasted in there by yours truly without him realizing it.  I found the bug and fixed it today in the version I will be posting very soon (hopefully on Thursday US Eastern time).  I have one more issue I'm working on, then the pull request will be ready.

                    Bill

                    1 Reply Last reply Reply Quote 0
                    • B
                      bera
                      last edited by

                      awesome…

                      i thought my configuration went south after the upgrade...  :o :o :o

                      keep up the good work....

                      many thanks...

                      1 Reply Last reply Reply Quote 0
                      • T
                        tehknowledge
                        last edited by

                        You rock Bill. Thank you!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.