Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Tailscale and Snort

    Tailscale
    2
    3
    828
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      ericreiss
      last edited by

      Hi,

      I want to setup Snort on all interfaces behind pfSense. That includes if there is a WireGuard connection and a Tailscale connection.

      The WireGuard has an interface assigned but Tailscale does not.

      I can choose the WireGuard interface in Snort.

      I tried assigning the unassigned tailscale0 interface but when I did this on a Netgate 6100 MAX late yesterday, I had a problem getting it to boot this morning. I had to connect to console and restore a saved config.

      I tried this on the pfSense running on a PC that I had first been experimenting with and assigned the tailscale0 interface but with no IPv4 assigned.

      Before trying a reboot, I tried bringing up the management interface on the Tailscale IP which was workign previously, but no go.

      Then I removed the assigned interface and still no management access on the Tailscale IP.

      I rebooted and was back to square one.

      Any idea how to get Tailscale assigned as an interface so that I can get Snort to see it?

      ~Eric

      1 Reply Last reply Reply Quote 0
      • mooncaptainM
        mooncaptain
        last edited by mooncaptain

        I found this on reddit
        some hints that may help

        I added a firewall alias list with login.tailscale.com and controlplane.tailscale.com

        tailscale Host(s) login.tailscale.com, controlplane.tailscale.com 
        

        I added the above alias to the pass lists in snort.

        The above seems to be working OK I only have tested by doing remote desktop from one tailscale machine to another.

        The connection failed with snort turned on and no pass list using the alias.

        don't forget to clear the block lists after making changes.

        mooncaptainM 1 Reply Last reply Reply Quote 0
        • mooncaptainM
          mooncaptain @mooncaptain
          last edited by

          @mooncaptain
          more urls to add to your pass list
          I found these are necessary after running snort for a while these url's started to get blocked.
          There may be more.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.