Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata IDS and IPS

    Scheduled Pinned Locked Moved IDS/IPS
    29 Posts 3 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      anx
      last edited by

      Hi guys,

      How to check if actually IDS is working? I have installed PfBlockerNG to block Adds only.

      Since then, I dont see any IDS alerts. Hmm

      1 Reply Last reply Reply Quote 0
      • DaddyGoD
        DaddyGo
        last edited by

        Hi,

        if you have the ability to run a KaliLinux virtual machine (or nativ), you will find all the tools for the different tests.
        I hope you meant pfBlockerNG -devel

        Cats bury it so they can't see it!
        (You know what I mean if you have a cat)

        1 Reply Last reply Reply Quote 1
        • A
          anx
          last edited by

          @DaddyGo said in Suricata IDS and IPS:

          pfBlockerNG -devel

          Yes, Devel version.

          Ok, will try with Kali. thanks

          bmeeksB 1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks @anx
            last edited by bmeeks

            @anx said in Suricata IDS and IPS:

            @DaddyGo said in Suricata IDS and IPS:

            pfBlockerNG -devel

            Yes, Devel version.

            Ok, will try with Kali. thanks

            If you have put Snort or Suricata on your LAN, you will need to direct your Kali machine towards that interface.

            With a properly tuned IDS you actually don't want to see any alerts as a normal thing. A few alerts now and then is what you would expect. For example, on my LAN my most recent Snort alerts are from April 30th of this year. And those were two HTTP_INSPECT preprocessor rules that mine and my wife's iPhones triggered. I run the IPS Balanced policy on my LAN along with a handful of the ET Open categories.

            Because I frequently need data to test with, I also run a Snort instance on my WAN and use a pair of ET Open "known bad IP address" categories enabled there purely to generate alerts for research. I run the Emerging CIARMY and Emerging DSHIELD categories on my WAN to generate that testing data. These two categories are actually just lists of IP addresses from known bad actors. They generate several hundred alerts per day on my WAN from the random Internet "noise" that is always there due to bots scanning for open ports and such.

            1 Reply Last reply Reply Quote 1
            • A
              anx
              last edited by

              Hi Guys

              Is there any way that when the pfBlockerNG -devel will block website, will actually block it with some information that is blocked by it? Instead that SSL is invalid? thanks
              Pfblocker.PNG

              bmeeksB 1 Reply Last reply Reply Quote 0
              • DaddyGoD
                DaddyGo
                last edited by DaddyGo

                @anx said in Suricata IDS and IPS:

                Hi Guys
                Is there any way that when the pfBlockerNG -devel will block website, will actually block it with some information that is blocked by it? Instead that SSL is invalid? thanks

                It is included in the name of "advertising"
                have you activated the AD block list?

                SSL:

                107bff27-30bb-4099-97b3-f0334cd7284a-image.png

                Cats bury it so they can't see it!
                (You know what I mean if you have a cat)

                1 Reply Last reply Reply Quote 1
                • bmeeksB
                  bmeeks @anx
                  last edited by

                  @anx said in Suricata IDS and IPS:

                  Hi Guys

                  Is there any way that when the pfBlockerNG -devel will block website, will actually block it with some information that is blocked by it? Instead that SSL is invalid? thanks
                  Pfblocker.PNG

                  You will get more responses and better answers to pfBlockerNG questions by posting your question over in the pfBlockerNG forum here: https://forum.netgate.com/category/62/pfblockerng.

                  1 Reply Last reply Reply Quote 1
                  • A
                    anx
                    last edited by anx

                    Yes, and i am happy to block it. But rather to have ssl invalid would be nice to have information that the pfBlockerNG blocked ad . I See that the blocker replaced the cert ? Tools.PNG

                    DaddyGoD 1 Reply Last reply Reply Quote 0
                    • DaddyGoD
                      DaddyGo @anx
                      last edited by DaddyGo

                      @anx

                      exactly:
                      (I know you love to learn, this is an older post (thread) but worth reading)
                      https://forum.netgate.com/topic/147785/pfblockerng-devel-dnsbl-cert-error

                      Reddit threads as well, if it is possible

                      edit:
                      BTW: Follow @bmeeks Bill's advice, if your question falls into this group (category) and you'd get to know pfBlockerNG, there are good professionals here.😉

                      https://forum.netgate.com/category/62/pfblockerng.

                      Cats bury it so they can't see it!
                      (You know what I mean if you have a cat)

                      1 Reply Last reply Reply Quote 1
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.