Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is pfBlocker and Snort compatable?

    Scheduled Pinned Locked Moved pfBlockerNG
    13 Posts 4 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      Velcro
      last edited by

      Do I go to the IPv4 tab, hit the "+" sign, create alias and add IP to "IPv4 Lists"?

      Thank you again..

      1 Reply Last reply Reply Quote 0
      • RonpfSR
        RonpfS
        last edited by

        Not the IPV4, the    Firewall / pfBlockerNG / Alerts tab

        2.4.5-RELEASE-p1 (amd64)
        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

        1 Reply Last reply Reply Quote 0
        • V
          Velcro
          last edited by

          I am on the Firewall/pfBlocker/Alerts tab but can't see where I can suppress an IP?

          Is there a setting in pfBlocker(maybe the pfBlocker General tab) that will allow me to suppress an IP for GeoIP?

          Thanks again for the help..

          1 Reply Last reply Reply Quote 0
          • RonpfSR
            RonpfS
            last edited by

            When you see this click on it to get more information about the pfblockerNG functionalities.

            Did you enabled suppression under  Firewall / pfBlockerNG / IP ?

            Alerts can be suppressed using the '+' icon in the Alerts tab and IPs are added to the IPv4 suppression custom list.
            For GeoIP/Blocked IPs in a CIDR other than /32 or /24, will need a 'Whitelist alias' w/ a List Action: 'Permit Outbound' Firewall rule.
            Only 'Deny' type Aliases can be suppressed!

            2.4.5-RELEASE-p1 (amd64)
            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

            1 Reply Last reply Reply Quote 0
            • V
              Velcro
              last edited by

              I enabled "Suppression" under Firewall/pfBlockerNG/General…however I do not know where "Firewall / pfBlockerNG / IP"  is...not sure if that is the same?

              1 Reply Last reply Reply Quote 0
              • RonpfSR
                RonpfS
                last edited by

                Well there is not suppression setting under Firewall / pfBlockerNG / General in the Development version. It's in the Firewall / pfBlockerNG / IP tab
                So maybe your tabs are different then mine.  :-[

                2.4.5-RELEASE-p1 (amd64)
                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                1 Reply Last reply Reply Quote 0
                • V
                  Velcro
                  last edited by

                  Seems basic but I cannot find a Firewall/pfblockerng/IP tab? See my screenshots attached.

                  I did find that a pfblockerNGSuppress alias was added however it is currently empty…is that where a suppress IPs go?

                  Might be a different screen to yours and pfBlocker doesn't work with a sg2440 running pfsense 2.3.4?

                  IMG_0145.JPG
                  IMG_0145.JPG_thumb
                  IMG_0144.JPG
                  IMG_0144.JPG_thumb

                  1 Reply Last reply Reply Quote 0
                  • RonpfSR
                    RonpfS
                    last edited by

                    As I stated, I am using a "later/under development" of pfblockerNG, so your tab are quite different from my version.

                    When you can suppress a IP , there is a blue "+" icon on the left of the IP.

                    So in you case, if you want to "Whitelist" the IPs without the "+" icon, you have to follow the instructions:

                    For GeoIP/Blocked IPs in a CIDR other than /32 or /24, will need a 'Whitelist alias' w/ a List Action: 'Permit Outbound' Firewall rule.
                    Only 'Deny' type Aliases can be suppressed!

                    But try to download the rules with a browser https://www.snort.org/downloads/#rule-downloads
                    the IP used on my side is 104.16.63.75

                    Maybe it's the domain name that is blocked.

                    2.4.5-RELEASE-p1 (amd64)
                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                    1 Reply Last reply Reply Quote 0
                    • V
                      Velcro
                      last edited by

                      Thanks RonpfS…I appreciate the help!

                      1 Reply Last reply Reply Quote 0
                      • BBcan177B
                        BBcan177 Moderator
                        last edited by

                        I believe that the Snort OpenAppID Detector Feed is based in South America…

                        "Experience is something you don't get until just after you need it."

                        Website: http://pfBlockerNG.com
                        Twitter: @BBcan177  #pfBlockerNG
                        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                        1 Reply Last reply Reply Quote 0
                        • R
                          Ramosel
                          last edited by

                          @BBcan177:

                          I believe that the Snort OpenAppID Detector Feed is based in South America…

                          Yep, Brazil…    this is the one you helped me with.  I don't use the country lists for that region.

                          TLD blacklist
                          br
                          edu.br

                          TLD whitelist
                          www.ifs.edu.br|200.133.48.21 # for SNORT OpenAppID rule
                          ifs.edu.br|200.133.48.21 # for SNORT OpenAppID rule
                          thor.ifs.edu.br|200.133.48.21 # SNORT OpenAppID rule

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.