<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort on Pfsense 2.4.4]]></title><description><![CDATA[<p dir="auto">Hi Guys,</p>
<p dir="auto">The blocked tab in snort is takinig a very long time to load. IPS is tuned and doesnt have that much of entries. any ideas what could becausing this?</p>
]]></description><link>https://forum.netgate.com/topic/152977/snort-on-pfsense-2-4-4</link><generator>RSS for Node</generator><lastBuildDate>Sat, 07 Mar 2026 18:10:52 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/152977.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 27 Apr 2020 01:42:56 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Snort on Pfsense 2.4.4 on Fri, 01 May 2020 01:29:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bmeeks">@<bdi>bmeeks</bdi></a> Thank you very much, i will take off some lists and check what happens</p>
]]></description><link>https://forum.netgate.com/post/909243</link><guid isPermaLink="true">https://forum.netgate.com/post/909243</guid><dc:creator><![CDATA[compuomari]]></dc:creator><pubDate>Fri, 01 May 2020 01:29:24 GMT</pubDate></item><item><title><![CDATA[Reply to Snort on Pfsense 2.4.4 on Thu, 30 Apr 2020 23:36:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/compuomari">@<bdi>compuomari</bdi></a> said in <a href="/post/909232">Snort on Pfsense 2.4.4</a>:</p>
<blockquote>
<p dir="auto">Hi, Thanks for your reply,</p>
<p dir="auto">I have 5-10 IP addresses in the block list. i also periodically flush that list. I am thinking of Pfblocker as i've recently added DNSBL lists, could those be the reason? otherwise my block lists are reasonable... i am not doing any reputation based blocking..</p>
<p dir="auto">would you like any logs from my system... if this may help?</p>
<p dir="auto">Cheers</p>
</blockquote>
<p dir="auto">Yes, most definitely the DNSBL will cause the problem if you have lots of IP lists (and most folks do with that option).</p>
]]></description><link>https://forum.netgate.com/post/909233</link><guid isPermaLink="true">https://forum.netgate.com/post/909233</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Thu, 30 Apr 2020 23:36:10 GMT</pubDate></item><item><title><![CDATA[Reply to Snort on Pfsense 2.4.4 on Thu, 30 Apr 2020 23:34:28 GMT]]></title><description><![CDATA[<p dir="auto">Hi, Thanks for your reply,</p>
<p dir="auto">I have 5-10 IP addresses in the block list. i also periodically flush that list. I am thinking of Pfblocker as i've recently added DNSBL lists, could those be the reason? otherwise my block lists are reasonable... i am not doing any reputation based blocking..</p>
<p dir="auto">would you like any logs from my system... if this may help?</p>
<p dir="auto">Cheers</p>
]]></description><link>https://forum.netgate.com/post/909232</link><guid isPermaLink="true">https://forum.netgate.com/post/909232</guid><dc:creator><![CDATA[compuomari]]></dc:creator><pubDate>Thu, 30 Apr 2020 23:34:28 GMT</pubDate></item><item><title><![CDATA[Reply to Snort on Pfsense 2.4.4 on Mon, 27 Apr 2020 13:52:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/compuomari">@<bdi>compuomari</bdi></a>:</p>
<p dir="auto">How many blocked IPs do you have? And are you running any other package that might be generating and or maintaining large <code>pf</code> tables?</p>
<p dir="auto">There is a known issue with the <code>pfctl</code> utility when it is manipulating large tables in the <code>pf</code> firewall engine. That issue is being investigated by the pfSense team. The problem seems to have come over with the update to FreeBSD 11.3/STABLE. The BLOCKED tab calls the <code>pfctl</code> utility to grab the list of IP addresses currently held in the <em>snort2c</em> table Snort uses for blocking hosts.</p>
<p dir="auto">You really need to be running the periodic task to remove blocked hosts if you do not already have that enabled. Go to the GLOBAL SETTINGS tab and enable the option to "Remove Blocked Hosts" and set it to a reasonable interval. I suggest 1 hour as a good time. That is enough to discourage port scanners and the like. There is no reason whatsoever to keep IPs in the blocked table for days or weeks. If the offending IP targets your box again, Snort will block it again. The 1-hour suggested blocked host interval is plenty of time to leave an IP blocked.</p>
<p dir="auto">If you have the "Remove Blocked Hosts" option enabled and still have slow page loading on the BLOCKED tab, then how many IPs are in that list?</p>
]]></description><link>https://forum.netgate.com/post/908383</link><guid isPermaLink="true">https://forum.netgate.com/post/908383</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Mon, 27 Apr 2020 13:52:40 GMT</pubDate></item></channel></rss>