Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata IOS blocked

    Scheduled Pinned Locked Moved IDS/IPS
    5 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      micropone
      last edited by

      which rule set has IOS apple updates and youtube listed… Cant watch youtube on mobile's

      thanks in advance

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        @micropone:

        which rule set has IOS apple updates and youtube listed… Cant watch youtube on mobile's

        thanks in advance

        My first suspicion would be alerts from the stream5 preprocessor.  It can give a lot of false positives in some environments.  You will need to look on the ALERTS tab to see which alerts are firing on your IOS devices.  Should be able to track things down using the IP addresses of the Apple devices to match up with alerts on the ALERTS tab.

        Bill

        1 Reply Last reply Reply Quote 0
        • M
          micropone
          last edited by

          thanks Bill…

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks
            last edited by

            @micropone:

            thanks Bill…

            Once you locate the offending alerts on the ALERTS tab, you can then decide if they are likely false positives.  If you conclude they are, you can simply disable those rules by clicking the red X icon in the column on the far right for GID:SID.

            Bill

            1 Reply Last reply Reply Quote 0
            • M
              micropone
              last edited by

              thanks I got it working…. and yes I red X'ed it...

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.