Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WAN Passlist Ignored

    Scheduled Pinned Locked Moved IDS/IPS
    3 Posts 2 Posters 335 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad
      last edited by NogBadTheBad

      Suricata 7.0.2_3 seems to be ignoring my passlist entry for my upstream IPv4 gateway and adding it to the snort2c table.

      Screenshot 2024-02-06 at 13.24.16.png

      Screenshot 2024-02-06 at 13.23.35.png

      Screenshot 2024-02-06 at 13.31.06.png

      I thought anything in the passlist was never blocked, any ideas ?

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @NogBadTheBad
        last edited by

        @NogBadTheBad read through https://forum.netgate.com/topic/184858/suricata-blocking-ips-on-passlist-legacy-mode-blocking-both/. Disabling checksum offloading was one solution.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        NogBadTheBadN 1 Reply Last reply Reply Quote 1
        • NogBadTheBadN
          NogBadTheBad @SteveITS
          last edited by

          @SteveITS Thanks, just changed the setting and given the router a reboot.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.