Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    white list url on snort

    Scheduled Pinned Locked Moved IDS/IPS
    5 Posts 3 Posters 692 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      heliop100
      last edited by

      Hi,

      Is it possible to whitelist an URL?

      The http://that.site.com I want to whitelist are on Akamai, and IP changes every time.
      Or it save (not sure how) to whitelist all Akamai by ASN? (I know it's possible on pfBlockerNG).

      Thanks.

      1 Reply Last reply Reply Quote 0
      • bmeeksB Offline
        bmeeks
        last edited by

        Snort does not support any type of changing or dynamic IP. If you have a list that updates, then you would need to restart Snort each time the list is updated. If you are willing to do that, then you could perhaps use the IP REP tab in Snort to accomplish a whitelist like you want.

        1 Reply Last reply Reply Quote 1
        • NogBadTheBadN Offline
          NogBadTheBad
          last edited by

          Here's the subnet details for their AS number:-

          Whois.txt

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          H 1 Reply Last reply Reply Quote 1
          • H Offline
            heliop100 @NogBadTheBad
            last edited by

            @NogBadTheBad said in white list url on snort:

            Here's the subnet details for their AS number:-

            Whois.txt

            Is it safe to whitelist all AKAMAI?

            NogBadTheBadN 1 Reply Last reply Reply Quote 0
            • NogBadTheBadN Offline
              NogBadTheBad @heliop100
              last edited by

              @heliop100

              If http://that.site.com/ keeps moving from one of their IP addresses to another its your only hope, can't vouch for if its safe or not.

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.