Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is pfBlocker and Snort compatable?

    Scheduled Pinned Locked Moved pfBlockerNG
    13 Posts 4 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RonpfSR
      RonpfS
      last edited by

      Looks at the Alerts Tab and suppress the IP or the Domain name that is blocked when pfblockerNG is active

      2.4.5-RELEASE-p1 (amd64)
      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

      1 Reply Last reply Reply Quote 0
      • V
        Velcro
        last edited by

        Do I go to the IPv4 tab, hit the "+" sign, create alias and add IP to "IPv4 Lists"?

        Thank you again..

        1 Reply Last reply Reply Quote 0
        • RonpfSR
          RonpfS
          last edited by

          Not the IPV4, the    Firewall / pfBlockerNG / Alerts tab

          2.4.5-RELEASE-p1 (amd64)
          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

          1 Reply Last reply Reply Quote 0
          • V
            Velcro
            last edited by

            I am on the Firewall/pfBlocker/Alerts tab but can't see where I can suppress an IP?

            Is there a setting in pfBlocker(maybe the pfBlocker General tab) that will allow me to suppress an IP for GeoIP?

            Thanks again for the help..

            1 Reply Last reply Reply Quote 0
            • RonpfSR
              RonpfS
              last edited by

              When you see this click on it to get more information about the pfblockerNG functionalities.

              Did you enabled suppression under  Firewall / pfBlockerNG / IP ?

              Alerts can be suppressed using the '+' icon in the Alerts tab and IPs are added to the IPv4 suppression custom list.
              For GeoIP/Blocked IPs in a CIDR other than /32 or /24, will need a 'Whitelist alias' w/ a List Action: 'Permit Outbound' Firewall rule.
              Only 'Deny' type Aliases can be suppressed!

              2.4.5-RELEASE-p1 (amd64)
              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

              1 Reply Last reply Reply Quote 0
              • V
                Velcro
                last edited by

                I enabled "Suppression" under Firewall/pfBlockerNG/General…however I do not know where "Firewall / pfBlockerNG / IP"  is...not sure if that is the same?

                1 Reply Last reply Reply Quote 0
                • RonpfSR
                  RonpfS
                  last edited by

                  Well there is not suppression setting under Firewall / pfBlockerNG / General in the Development version. It's in the Firewall / pfBlockerNG / IP tab
                  So maybe your tabs are different then mine.  :-[

                  2.4.5-RELEASE-p1 (amd64)
                  Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                  Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                  1 Reply Last reply Reply Quote 0
                  • V
                    Velcro
                    last edited by

                    Seems basic but I cannot find a Firewall/pfblockerng/IP tab? See my screenshots attached.

                    I did find that a pfblockerNGSuppress alias was added however it is currently empty…is that where a suppress IPs go?

                    Might be a different screen to yours and pfBlocker doesn't work with a sg2440 running pfsense 2.3.4?

                    IMG_0145.JPG
                    IMG_0145.JPG_thumb
                    IMG_0144.JPG
                    IMG_0144.JPG_thumb

                    1 Reply Last reply Reply Quote 0
                    • RonpfSR
                      RonpfS
                      last edited by

                      As I stated, I am using a "later/under development" of pfblockerNG, so your tab are quite different from my version.

                      When you can suppress a IP , there is a blue "+" icon on the left of the IP.

                      So in you case, if you want to "Whitelist" the IPs without the "+" icon, you have to follow the instructions:

                      For GeoIP/Blocked IPs in a CIDR other than /32 or /24, will need a 'Whitelist alias' w/ a List Action: 'Permit Outbound' Firewall rule.
                      Only 'Deny' type Aliases can be suppressed!

                      But try to download the rules with a browser https://www.snort.org/downloads/#rule-downloads
                      the IP used on my side is 104.16.63.75

                      Maybe it's the domain name that is blocked.

                      2.4.5-RELEASE-p1 (amd64)
                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                      1 Reply Last reply Reply Quote 0
                      • V
                        Velcro
                        last edited by

                        Thanks RonpfS…I appreciate the help!

                        1 Reply Last reply Reply Quote 0
                        • BBcan177B
                          BBcan177 Moderator
                          last edited by

                          I believe that the Snort OpenAppID Detector Feed is based in South America…

                          "Experience is something you don't get until just after you need it."

                          Website: http://pfBlockerNG.com
                          Twitter: @BBcan177  #pfBlockerNG
                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                          1 Reply Last reply Reply Quote 0
                          • R
                            Ramosel
                            last edited by

                            @BBcan177:

                            I believe that the Snort OpenAppID Detector Feed is based in South America…

                            Yep, Brazil…    this is the one you helped me with.  I don't use the country lists for that region.

                            TLD blacklist
                            br
                            edu.br

                            TLD whitelist
                            www.ifs.edu.br|200.133.48.21 # for SNORT OpenAppID rule
                            ifs.edu.br|200.133.48.21 # for SNORT OpenAppID rule
                            thor.ifs.edu.br|200.133.48.21 # SNORT OpenAppID rule

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.