<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort Preprocessors block IPs from HOME_NET]]></title><description><![CDATA[<p dir="auto">Hi there,</p>
<p dir="auto">I hope to get any replys to this post. I configured PfSense 2.0.1 Snort 2.9.2.3 pkg v. 2.5.1 very often now, and I have successfully set my HOME_NET variable in the snort configuration (/var/local/etc/snort/igb0…./snort.conf). Normal rules dont get triggered if they are caused by IPs from my Homenet. But still, alerts caused by my subnet appear, if they are detected by proprecessors like "HTTP INSPECT" or "ssp_ssl". Is there an option which has to be activated to whitelist my subnet-IPs?<br />
Is there any way to change the configuration of preprocessors (edit manually the config files?) or do I have to disable them to avoid alerts?</p>
]]></description><link>https://forum.netgate.com/topic/49750/snort-preprocessors-block-ips-from-home_net</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Jul 2026 23:02:25 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/49750.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 25 Oct 2012 16:11:09 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Snort Preprocessors block IPs from HOME_NET on Thu, 22 Nov 2012 10:52:10 GMT]]></title><description><![CDATA[<p dir="auto">well thats another problem. the whitelisted ip's are not being blocked, only if you enter a CIDR like 192.168.20.0/24, i had to type all 256 ips into an pfsense alias to prevent my subnet from being blocked (because of blocking "both", dst and src(which can change in some rules))</p>
<p dir="auto">currently i tuned most of the preprocessors by removing the check marks in the configuration page and entered a different preprocessor configuration in "Advanced configuration pass through". Works very good, but I turned most of the preprocessor alerts to reduce false alerts.</p>
]]></description><link>https://forum.netgate.com/post/365471</link><guid isPermaLink="true">https://forum.netgate.com/post/365471</guid><dc:creator><![CDATA[moe2006]]></dc:creator><pubDate>Thu, 22 Nov 2012 10:52:10 GMT</pubDate></item><item><title><![CDATA[Reply to Snort Preprocessors block IPs from HOME_NET on Tue, 20 Nov 2012 21:09:49 GMT]]></title><description><![CDATA[<p dir="auto">Hmm… all the aliases I include in snort whitelists have an underscore in the name - maybe that's why they are failing (ie. whitelisted ip's getting blocked).  I'll try to update here if I find that to be the case.</p>
]]></description><link>https://forum.netgate.com/post/365162</link><guid isPermaLink="true">https://forum.netgate.com/post/365162</guid><dc:creator><![CDATA[jnorell]]></dc:creator><pubDate>Tue, 20 Nov 2012 21:09:49 GMT</pubDate></item><item><title><![CDATA[Reply to Snort Preprocessors block IPs from HOME_NET on Sat, 03 Nov 2012 09:50:00 GMT]]></title><description><![CDATA[<p dir="auto">I had the same problem, my fix was that in the name of the ip aliases I put the sign "_" between words and after removing that from the alias name and renaming the alias with only letters it worked.</p>
<p dir="auto">I also checked the snort config in /usr/local/etc/snort/snort_&lt;if&gt;/snort.conf to see if the ips are in the homenet. If they are not added there is a problem with the aliases.&lt;/if&gt;</p>
]]></description><link>https://forum.netgate.com/post/362747</link><guid isPermaLink="true">https://forum.netgate.com/post/362747</guid><dc:creator><![CDATA[slim0801]]></dc:creator><pubDate>Sat, 03 Nov 2012 09:50:00 GMT</pubDate></item></channel></rss>