Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is pfBlocker and Snort compatable?

    Scheduled Pinned Locked Moved pfBlockerNG
    13 Posts 4 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RonpfSR
      RonpfS
      last edited by

      Not the IPV4, the    Firewall / pfBlockerNG / Alerts tab

      2.4.5-RELEASE-p1 (amd64)
      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

      1 Reply Last reply Reply Quote 0
      • V
        Velcro
        last edited by

        I am on the Firewall/pfBlocker/Alerts tab but can't see where I can suppress an IP?

        Is there a setting in pfBlocker(maybe the pfBlocker General tab) that will allow me to suppress an IP for GeoIP?

        Thanks again for the help..

        1 Reply Last reply Reply Quote 0
        • RonpfSR
          RonpfS
          last edited by

          When you see this click on it to get more information about the pfblockerNG functionalities.

          Did you enabled suppression under  Firewall / pfBlockerNG / IP ?

          Alerts can be suppressed using the '+' icon in the Alerts tab and IPs are added to the IPv4 suppression custom list.
          For GeoIP/Blocked IPs in a CIDR other than /32 or /24, will need a 'Whitelist alias' w/ a List Action: 'Permit Outbound' Firewall rule.
          Only 'Deny' type Aliases can be suppressed!

          2.4.5-RELEASE-p1 (amd64)
          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

          1 Reply Last reply Reply Quote 0
          • V
            Velcro
            last edited by

            I enabled "Suppression" under Firewall/pfBlockerNG/General…however I do not know where "Firewall / pfBlockerNG / IP"  is...not sure if that is the same?

            1 Reply Last reply Reply Quote 0
            • RonpfSR
              RonpfS
              last edited by

              Well there is not suppression setting under Firewall / pfBlockerNG / General in the Development version. It's in the Firewall / pfBlockerNG / IP tab
              So maybe your tabs are different then mine.  :-[

              2.4.5-RELEASE-p1 (amd64)
              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

              1 Reply Last reply Reply Quote 0
              • V
                Velcro
                last edited by

                Seems basic but I cannot find a Firewall/pfblockerng/IP tab? See my screenshots attached.

                I did find that a pfblockerNGSuppress alias was added however it is currently empty…is that where a suppress IPs go?

                Might be a different screen to yours and pfBlocker doesn't work with a sg2440 running pfsense 2.3.4?

                IMG_0145.JPG
                IMG_0145.JPG_thumb
                IMG_0144.JPG
                IMG_0144.JPG_thumb

                1 Reply Last reply Reply Quote 0
                • RonpfSR
                  RonpfS
                  last edited by

                  As I stated, I am using a "later/under development" of pfblockerNG, so your tab are quite different from my version.

                  When you can suppress a IP , there is a blue "+" icon on the left of the IP.

                  So in you case, if you want to "Whitelist" the IPs without the "+" icon, you have to follow the instructions:

                  For GeoIP/Blocked IPs in a CIDR other than /32 or /24, will need a 'Whitelist alias' w/ a List Action: 'Permit Outbound' Firewall rule.
                  Only 'Deny' type Aliases can be suppressed!

                  But try to download the rules with a browser https://www.snort.org/downloads/#rule-downloads
                  the IP used on my side is 104.16.63.75

                  Maybe it's the domain name that is blocked.

                  2.4.5-RELEASE-p1 (amd64)
                  Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                  Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                  1 Reply Last reply Reply Quote 0
                  • V
                    Velcro
                    last edited by

                    Thanks RonpfS…I appreciate the help!

                    1 Reply Last reply Reply Quote 0
                    • BBcan177B
                      BBcan177 Moderator
                      last edited by

                      I believe that the Snort OpenAppID Detector Feed is based in South America…

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      1 Reply Last reply Reply Quote 0
                      • R
                        Ramosel
                        last edited by

                        @BBcan177:

                        I believe that the Snort OpenAppID Detector Feed is based in South America…

                        Yep, Brazil…    this is the one you helped me with.  I don't use the country lists for that region.

                        TLD blacklist
                        br
                        edu.br

                        TLD whitelist
                        www.ifs.edu.br|200.133.48.21 # for SNORT OpenAppID rule
                        ifs.edu.br|200.133.48.21 # for SNORT OpenAppID rule
                        thor.ifs.edu.br|200.133.48.21 # SNORT OpenAppID rule

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.