Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Easypass rules are not sticking

    IDS/IPS
    2
    3
    20
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Skozzy last edited by

      I have been getting some legit traffic blocked by snort rules. So, I went into the snort2c tables to find the specific address which was being blocked and manually deleted it. I then went into STATUS>SYSTEM LOGS>FIREWALL>NORMAL VIEW and created an easy pass rule in order to pass the traffic. Then the traffic passed, cool. I went to reload the site but it was blocked again. I then rememebered that I may have to run a forced update in order to save the changes.
      So, i repeated all of my steps and ran the update. Afterwards the traffic once again passed...but only once before getting blocked again and added to the snort2c table again. I went in to look at my rules and see my two easy list rules which i created for that specific address but the traffic is still getting blocked. I am not sure why this is happening. Do I have to disable the whole rule that was triggering snort?
      I am at a loss.

      1 Reply Last reply Reply Quote 0
      • bmeeks
        bmeeks last edited by

        Easy Pass rules are for the pfSense firewall engine and not for Snort. If you want to prevent Snort from blocking a particular IP address or netblock, then you must create a Pass List entry. Or you can simply suppress the rule that is triggering. That's what I would do (suppress that rule). You can suppress by GID:SID and thus disable the rule for all devices, or you can choose to suppress by IP and disable the rule for only selected devices matching the IP. Hover over the little "plus" icons on the ALERTS tab and tooltips will appear explaining each icon.

        1 Reply Last reply Reply Quote 1
        • S
          Skozzy last edited by

          Sorry for the late reply, you were correct. I created a passlist entry and then removed the IP from the blocked table and, boom. No more issues reaching the host.

          Thank you again bmeeks, you are a wizard.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post

          Products

          • Platform Overview
          • TNSR
          • pfSense Plus
          • Appliances

          Services

          • Training
          • Professional Services

          Support

          • Subscription Plans
          • Contact Support
          • Product Lifecycle
          • Documentation

          News

          • Media Coverage
          • Press
          • Events

          Resources

          • Blog
          • FAQ
          • Find a Partner
          • Resource Library
          • Security Information

          Company

          • About Us
          • Careers
          • Partners
          • Contact Us
          • Legal
          Our Mission

          We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

          Subscribe to our Newsletter

          Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

          © 2021 Rubicon Communications, LLC | Privacy Policy