Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata Not Blocking legacy mode

    Scheduled Pinned Locked Moved IDS/IPS
    76 Posts 5 Posters 21.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bmeeksB
      bmeeks @everfree
      last edited by

      @everfree said in Suricata Not Blocking legacy mode:

      where is the code about the custom output plugin??

      I don't think it is a loading issue, because I can use it before.

      But there have also been quite a number of changes within other parts of the Suricata binary over the last few years upstream that are not directly part of the custom blocking plugin used on pfSense. This makes it hard to nail down what might be the culprit; especially when the problem is not reproducible in a test environment.

      1 Reply Last reply Reply Quote 0
      • everfreeE
        everfree
        last edited by

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • N
          nn14
          last edited by

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • N
            nn14
            last edited by nn14

            Hi bmeeks:
            Do you know how to confirm that the custom blocking plugin may lose alerts?

            1 Reply Last reply Reply Quote 0
            • bmeeksB
              bmeeks
              last edited by bmeeks

              I have submitted a Pull Request with the custom blocking module changes that should hopefully address the "no blocks" issue identified in this thread. I've asked that the pull request be merged this Monday, September 30th. So a new Suricata package (version 4.1.5) should show up for the pfSense-2.4.4_p3 RELEASE branch sometime Monday.

              1 Reply Last reply Reply Quote 1
              • everfreeE
                everfree
                last edited by

                1.png

                Yes, it works, it's back back back.
                thanks. bmeeks.

                bmeeksB 1 Reply Last reply Reply Quote 0
                • bmeeksB
                  bmeeks @everfree
                  last edited by

                  @everfree said in Suricata Not Blocking legacy mode:

                  1.png

                  Yes, it works, it's back back back.
                  thanks. bmeeks.

                  You're welcome. I'm still puzzled why that variable was not always getting set to NULL in the SCRadixFindKeyBestMatchIPv4() function when the IP was not in a Pass List. I need to study that function carefully to see what's going on. Might be a bug within that code that needs reporting upstream.

                  1 Reply Last reply Reply Quote 1
                  • N
                    nn14
                    last edited by nn14

                    Dear bmeeks:
                    We appreciate your effort to solve this issue,
                    Thanks for your significant contribution to this community.
                    Thank you!

                    1 Reply Last reply Reply Quote 0
                    • everfreeE
                      everfree
                      last edited by

                      2.png

                      still have some loss, sad >.<

                      1 Reply Last reply Reply Quote 0
                      • everfreeE
                        everfree
                        last edited by

                        Still waiting, hope it will be fixed.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.