Suricata IDS 1.4.6 BETA package update v0.3 released
-
Noticed something else this morning, the cron job that removes IPs from snort2c seems to disappears after a reboot. I have to go to into the global tab and save it so the job is recreated.
EDIT: Nevermind… Its not because of a reboot... When I make changes to snort, it removes the cron job because I deactivated blocking in snort
You can have lots of weird issues if you run both Snort and Suricata in blocking mode because for the moment they share the same pf table (the snort2c table).
Bill
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.