Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata processes packets even though source IPs are blocked

    Scheduled Pinned Locked Moved IDS/IPS
    3 Posts 2 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      agis
      last edited by

      Hello all,

      I've been moving IPs blocked by Suricata to a couple of firewall aliases in order to completely block them and save some CPU time. The aliases are then used in floating rules to block all incoming IPv4 and IPv6 traffic. The problem I have is that these IPs have started reappearing in the Suricata blocked IPs.

      I think the problem started either a couple of pfSense updates ago, or when the alias holding the IP addresses grew big (150-200 IPs) … or I've completely misunderstood how Suricata works and it processes traffic before the firewall.

      Has anyone seen this problem before? Could someone help?

      Thanks so much in advance

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        This is nothing new…. In pfSense, Snort/Suricata (non-IPS mode) act on a copy of all the packets since the traffic is in promiscuous mode. So even if the firewall is blocking IPs, the IDS/IPS is still analyzing the "copy" of the original packets and reporting on them as per the defined Rules...

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • A
          agis
          last edited by

          I see… Now it makes sense ... and I should've thought of that :(

          Thanks a lot

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.