<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Suricata in legacy mode block entire tor category with SID management]]></title><description><![CDATA[<p dir="auto">Hi all,<br />
i am new with pfsense and Suricata as well.<br />
I have installed suricata packages and set it in IPS mode (block).<br />
I am setting in drop some rules one by one but I need to automatic do this job with the SID management feature.<br />
I tried to add a new dropsid_custom.conf file as belos</p>
<h1><a class="anchor-offset" name="start"></a>START</h1>
<p dir="auto">et-tor</p>
<h1><a class="anchor-offset" name="end"></a>END</h1>
<p dir="auto">I have applied the file to the Drop SID list on the interfaces and check "rebuild" before save.<br />
No categories or rules are using my file.<br />
can you help me please?</p>
<p dir="auto">thanks in advance</p>
<p dir="auto">L.</p>
]]></description><link>https://forum.netgate.com/topic/172634/suricata-in-legacy-mode-block-entire-tor-category-with-sid-management</link><generator>RSS for Node</generator><lastBuildDate>Wed, 10 Jun 2026 08:50:40 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/172634.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 05 Jun 2022 10:14:10 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Suricata in legacy mode block entire tor category with SID management on Mon, 06 Jun 2022 08:01:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bmeeks">@<bdi>bmeeks</bdi></a><br />
Hi bmeeks,<br />
Thanks for your answer.<br />
Greats, I have changed the category name into my Sid file and it perfectly works.<br />
Appreciate.</p>
<p dir="auto">BR</p>
<p dir="auto">L.</p>
]]></description><link>https://forum.netgate.com/post/1045358</link><guid isPermaLink="true">https://forum.netgate.com/post/1045358</guid><dc:creator><![CDATA[LucaA]]></dc:creator><pubDate>Mon, 06 Jun 2022 08:01:19 GMT</pubDate></item><item><title><![CDATA[Reply to Suricata in legacy mode block entire tor category with SID management on Sun, 05 Jun 2022 18:06:08 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lucaa">@<bdi>lucaa</bdi></a> said in <a href="/post/1045295">Suricata in legacy mode block entire tor category with SID management</a>:</p>
<blockquote>
<p dir="auto">Hi all,<br />
i am new with pfsense and Suricata as well.<br />
I have installed suricata packages and set it in IPS mode (block).<br />
I am setting in drop some rules one by one but I need to automatic do this job with the SID management feature.<br />
I tried to add a new dropsid_custom.conf file as belos</p>
<h1><a class="anchor-offset" name="start"></a>START</h1>
<p dir="auto">et-tor</p>
<h1><a class="anchor-offset" name="end"></a>END</h1>
<p dir="auto">I have applied the file to the Drop SID list on the interfaces and check "rebuild" before save.<br />
No categories or rules are using my file.<br />
can you help me please?</p>
<p dir="auto">thanks in advance</p>
<p dir="auto">L.</p>
</blockquote>
<p dir="auto">Your rule category name is incorrect. You must use the name as shown on the CATEGORIES tab. So without looking to refresh my memory, I think instead of "et-tor" you should have "emerging-tor". Go look at the actual rule category filenames on the CATEGORIES tab in Suricata. That's the name you should use when wanting the SID MGMT feature to "match" a category name.</p>
]]></description><link>https://forum.netgate.com/post/1045322</link><guid isPermaLink="true">https://forum.netgate.com/post/1045322</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Sun, 05 Jun 2022 18:06:08 GMT</pubDate></item></channel></rss>