Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata Host Not Removed From Blocked Table

    Scheduled Pinned Locked Moved IDS/IPS
    4 Posts 3 Posters 528 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      PFgate
      last edited by

      I have selected the red X (Remove host from Blocked Table) for host 134.195.207.8 multiple times. Wondering why it keeps coming back. What am I misunderstanding?

      cbe1ba17-0285-4f1d-85cf-4f651da22300-image.png

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @PFgate
        last edited by

        @pfgate Removing it will remove it once. Further alerts will block it again. If you want to permanently ignore it you can click the + icon there to suppress the alert so that rule doesn't trigger for that IP. Or else you can add it to a pass list (and assign the pass list to the Suricata interface, and restart Suricata) to bypass all rules for that IP.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • bmeeksB
          bmeeks
          last edited by bmeeks

          @SteveITS is 100% correct. That IP address is triggering the same rule over and over. So when you remove it from the BLOCKS table, it is going to be put back as soon as that IP address triggers the same rule again.

          You need to address this either by suppressing that rule for that IP address, or by adding the IP address to a Pass List so that it is not blocked. The difference between "suppressing" and a "pass list" is as follows:

          A suppressed rule will not fire at all for the condition specified. You can suppress rules by source or destination IP address. You can also suppress them by Signature ID, but that is really the same as disabling the rule. There are icons for all these actions on the ALERTS tab shown on the line for each alert. Hover over the icons and a tooltip will pop up explaining what the icon does. Suppressing by IP means that if the target IP causes the rule to trigger, the alert will be suppressed (not logged and thus not show up in the ALERTS tab view) and therefore will not result in a block.

          A Pass List contains a group of IP addresses that are never blocked. The rules will still trigger and alerts will show on the ALERTS tab for those IP addresses, but the IP will not get blocked.

          1 Reply Last reply Reply Quote 0
          • P
            PFgate
            last edited by

            @SteveITS @bmeeks Thanks. I will add this great info to my documentation.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.