Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Newbie questions regarding SNORT on pfsense

    pfSense Packages
    3
    5
    1117
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bwong3351 last edited by

      When I "Remove" an IP from the block list,will it automatically be added to the white-list? If so is there any way for me to edit the whitelist?

      Thanks

      1 Reply Last reply Reply Quote 0
      • J
        judex last edited by

        Removed IPs are not added to the whitelist.
        You can edit or create a new whitelist under Firewall/Aliases and use that created/modified alias under Services -> Snort -> Whitelists

        Best wishes,

        Judex

        2.1-RELEASE (amd64)
        built on Wed Sep 11 18:17:48 EDT 2013
        FreeBSD 8.3-RELEASE-p11

        1 Reply Last reply Reply Quote 0
        • B
          bwong3351 last edited by

          Thanks for the quick reply

          1 Reply Last reply Reply Quote 0
          • S
            simi8 last edited by

            so…what does "remove from isp" do ?

            1 Reply Last reply Reply Quote 0
            • B
              bwong3351 last edited by

              Is a temp pass. This will only work if you have auto black IP turn on.

              Example if a IP was blocked due to some rule. By removing it you allow a tmp pass through but if the IP trip the same rule (or other rule) it will get block again.

              If you add the IP to the WL, Snort will completely skip it.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post