<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Suricata blocking IPs that are on the passlist]]></title><description><![CDATA[<p dir="auto">I have Suricata running in legacy IPS mode.</p>
<p dir="auto">My passlist has all the default boxes checked, including "Add VPN Addresses to the list."</p>
<p dir="auto">I also have a passlist alias selected which has one or two IPs (that are not otherwise on the passlist)</p>
<p dir="auto">I have the passlist applied to my interface in Suricata.</p>
<p dir="auto">I just had a situation where two IPs on one of my remote networks, which is connected via a site-to-site VPN on the pfSense were blocked.</p>
<p dir="auto">I verified that the network range (in this case 192.168.121.1/24) is listed in the passlist when clicking View List for the pass list on the interface options screen in Suricata.</p>
<p dir="auto">Any ideas on what could be going on and why these IPs are getting blocked even though the range they are in is on the pass list?</p>
]]></description><link>https://forum.netgate.com/topic/113539/suricata-blocking-ips-that-are-on-the-passlist</link><generator>RSS for Node</generator><lastBuildDate>Tue, 10 Mar 2026 09:58:42 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/113539.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 24 Mar 2017 22:40:50 GMT</pubDate><ttl>60</ttl></channel></rss>