Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Scheduled emptying of block list?

    Scheduled Pinned Locked Moved IDS/IPS
    3 Posts 2 Posters 792 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dhboyd26
      last edited by

      I know I can schedule things via cron and the like, but is there a command to empty the Snort/Suricata blocklist on a regular basis?  I know I can set how long a block lasts, but I want to be able to just empty the list on a regular basis.  We are having a tough time figuring out what rules are causing some of our critical services to be blocked, so for now, until I can sort it all out, i want to just dump the block list on a regular basis.

      I've searched but not found anything on this, please simply point me in the right direction if you know there is a solution and I just couldn't search properly.

      Thanks.

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        For the first few weeks or so, best to use Snort/Suricata in Non-Blocking mode…. This gives you time to tune it to your network without actually blocking anything...

        otherwise this command will flush the table...

        pfctl -t snort2c -T flush
        

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • D
          dhboyd26
          last edited by

          Thanks.  I would love to be running in NB mode, but we're in full swing for classes and if I run in NB mode the RIAA, MPAA and anyone else with copyright grievances will be breathing down my neck… students just won't turn off their BitTorrent clients.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.