Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    snort blocking dns servers

    Scheduled Pinned Locked Moved IDS/IPS
    5 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rogg
      last edited by

      I have pfsense working as gateway and there working snort. When i have malware alert snort blocking dns server and internet stop working in all lan. Is it possible to only kill connections and not to ban ip ?

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        You need to examine the Snort rules that are alerting and blocking to determine if they are false positives in your environment. Google searches are a big help with this. There is also an old message thread in this forum about "suppress rules" for reducing false positives.

        You can also add the IP of your DNS server to a Pass List, although they should be included in the default pass list if the IP addresses are entered in the pfSense setup.

        1 Reply Last reply Reply Quote 0
        • R
          rogg
          last edited by

          its other trouble - snort blocking dns ip address which is whitelisted in snort configuration.

          bmeeksB 1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by

            What rule is being triggered, if I try and ping fred.top I see the following in my logs but its not blocking:-

            0_1533636757230_Untitled.png

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • bmeeksB
              bmeeks @rogg
              last edited by

              @rogg said in snort blocking dns servers:

              its other trouble - snort blocking dns ip address which is whitelisted in snort configuration.

              When Snort blocks on a triggered alert, it can block either the Source IP, Destination IP or Both depending on a setting on the Interface Configuration tab. As @NogBadTheBad stated, check the Alerts tab to see which rule or rules are being triggered and blocking. You can filter on the tab by IP address to help in locating rules with your DNS server IP in either the SRC or DST columns.

              1 Reply Last reply Reply Quote 1
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.