Suricata not blocking anything
-
I just set up Suricata. Using Open Emerging Threat Rules. I have Legacy mode blocking enabled on my WAN interface. I ran nmap on my WAN IP and saw all the alerts come through, but nothing was blocked. Did I misconfigure something?
-
@xoomdust You forgot to check block on drop.
You will need to change the alert to a drop.
-
@NollipfSense not that it would be ideal, but wouldn't my configuration be blocking all alerts though?
-
@xoomdust said in Suricata not blocking anything:
I ran nmap on my WAN IP and saw all the alerts come through, but nothing was blocked.
That's what you said!
-
@NollipfSense Right, but your screenshot shows what I'm talking about. "When not checked, any rule action (ALERT or DROP) will generate a block of the offending host."
It's not checked, yet alerts are not generating blocks of the offending host I'm seeing alerts for.
-