Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort blocking my local IP

    Scheduled Pinned Locked Moved pfSense Packages
    8 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • mudmanc4M
      mudmanc4
      last edited by

      I've created an alias, added this to the whitelist, restart the interface - still continues to block the IP.

      I have another way in obviously through the backend, however this is blocking all front end services to the IP

      What is it I do not understand about whitelisting and IP through snort ?

      Any help is appreciated.

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        Check the Snort2c table in Diagnostic:Tables to see if the IP is listed.

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • mudmanc4M
          mudmanc4
          last edited by

          I have no 'Tables' in Diagnostic

          There is ARPtable & NDPtable

          I should be more familiar , but this is the first time using snort on this level in pfsense.

          Thanks

          1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator
            last edited by

            In Diagnostic:Tables you should get a drop down menu where you can select the table "snort2C"

            https://x.x.x.x:xxxx/diag_tables.php  (Enter you ip and port in the x's)

            What version of pfSense are you running?

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • mudmanc4M
              mudmanc4
              last edited by

              Yes the IP that being blocked is in that file, with a couple dozen others.

              Thanks for getting me in there !

              1 Reply Last reply Reply Quote 0
              • bmeeksB
                bmeeks
                last edited by

                @mudmanc4:

                Yes the IP that being blocked is in that file, with a couple dozen others.

                Thanks for getting me in there !

                Two things to remember.

                First, when modifying the Whitelist, you must make sure the Snort interface is using the one you modified.  You can create multiple whitelists and give them different names.  Folks do this that run Snort on multiple interfaces.  To make sure Snort is using the correct whitelist, go to the Snort menu, click the Interfaces tab, and then click on the e icon beside the Snort instance you want to edit.  This will open the edit window for that interface. Scroll down near the bottom of the page and find the section for the whitelist.  Make sure the value in the drop-down selection matches the name of the whitelist you created (or edited).  Click the SAVE button to save the change.

                Another thing to remember is that when changing the whitelist, you must restart Snort for it to pick up the change.

                Last item I will throw in is that you cannot use FQDN Aliases.  The alias selection process should not have allowed that anyway, but just offering a reminder.

                Bill

                1 Reply Last reply Reply Quote 0
                • mudmanc4M
                  mudmanc4
                  last edited by

                  I have changed the whitelist for that interface to the one created earlier,  restart snort, and made various protocol requests - no blocking that I can see at this point.

                  Big info from you on this, much appreciated bmeeks !

                  1 Reply Last reply Reply Quote 0
                  • bmeeksB
                    bmeeks
                    last edited by

                    @mudmanc4:

                    I have changed the whitelist for that interface to the one created earlier,  restart snort, and made various protocol requests - no blocking that I can see at this point.

                    Big info from you on this, much appreciated bmeeks !

                    Thank you.  Glad it's working for you now.  One item on my TODO list is to update the Snort package documentation and then include links to it from various spots in the package.

                    Bill

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.