Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block Sender (not Recipient) for just 1 or more Rule(s) in SNORT?

    Scheduled Pinned Locked Moved IDS/IPS
    2 Posts 2 Posters 368 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      TMC1
      last edited by

      Is there a way to set 1 Alert/Block Rule to block only the Sender - without setting the Global IDS setting. We have a couple of rules that we'd like to block the Sender IP on, but not the Recipient - while for most/all of them, we want to block both; is there a method to do this? Any input is appreciated!

      bmeeksB 1 Reply Last reply Reply Quote 0
      • bmeeksB Offline
        bmeeks @TMC1
        last edited by

        @TMC1 said in Block Sender (not Recipient) for just 1 or more Rule(s) in SNORT?:

        Is there a way to set 1 Alert/Block Rule to block only the Sender - without setting the Global IDS setting. We have a couple of rules that we'd like to block the Sender IP on, but not the Recipient - while for most/all of them, we want to block both; is there a method to do this? Any input is appreciated!

        No, the blocking is not that granular. The setting for which IP to block (SRC, DST or BOTH) is global.

        Depending on exactly what you are wanting to do, you could perhaps create one or two custom rules that only trigger for that one Sender IP you wish to block. But that also is dependent on exactly what traffic you want to trigger on.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.