Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rebooting pfsense router removes snort blocked hosts?

    Scheduled Pinned Locked Moved pfSense Packages
    5 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dmitripr
      last edited by

      Hello,

      I have just rebooted my new pfsense router for the first time after installing snort a couple of days ago. While I can see all the old alerts that were generated prior to reboot, when I check "blocked" tab no hosts were displayed (as if they've been cleared). Prior to reboot I had about 130 records there.

      Is this normal behavior? When I reboot pfsense, I loose all the blocked hosts? If not normal, what could be the problem here? Any way to get the blocked hosts back from the alerts that were generated (which were actually saved after reboot)?

      Thanks a lot!
      Dmitri

      2.1.4-RELEASE (amd64)
      built on Fri Jun 20 12:59:50 EDT 2014
      FreeBSD 8.3-RELEASE-p16

      snort 2.9.6.0 pkg v3.0.13

      1 Reply Last reply Reply Quote 0
      • D
        dmitripr
        last edited by

        Nevermind. I found my answer. Apparently this is normal behavior.

        https://forum.pfsense.org/index.php?topic=66904.0

        Thank you!

        1 Reply Last reply Reply Quote 0
        • BBcan177B
          BBcan177 Moderator
          last edited by

          Hi dmitripr,

          In Snorts Global Settings, you have the option to set:

          Remove Blocked Hosts Interval

          Which can be set to Never, which shouldn't clear the table. I haven't noticed that its cleared at reboot as I seldom reboot the pfSense Box.

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • D
            dmitripr
            last edited by

            @BBcan177:

            Hi dmitripr,

            In Snorts Global Settings, you have the option to set:

            Remove Blocked Hosts Interval

            Which can be set to Never, which shouldn't clear the table. I haven't noticed that its cleared at reboot as I seldom reboot the pfSense Box.

            Yes, I saw that. I do have it set for never, but I don't think it affects the behavior after reboot. Based on the topic I link in my second message, looks like the blocked hosts are removed when filter is reset – which would happen at reboot. That's outside of Snort's control.

            Thanks for the message, though!

            1 Reply Last reply Reply Quote 0
            • bmeeksB
              bmeeks
              last edited by

              @dmitripr:

              … Based on the topic I link in my second message, looks like the blocked hosts are removed when filter is reset -- which would happen at reboot. That's outside of Snort's control.

              Thanks for the message, though!

              Correct.  On a reboot all of the pf tables are cleared, including the <snor2c>table utilized by Snort.

              Bill</snor2c>

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.