Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Snort suppress list not working ?

    pfSense Packages
    3
    5
    1289
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      godtor last edited by

      Hello,

      i have problems with some ruls that are fals-pozitive like:
      (http_inspect) NO CONTENT-LENGTH OR TRANSFER-ENCODING IN HTTP RESPONSE
      (http_inspect) BARE BYTE UNICODE ENCODING
      (http_inspect) UNKNOWN METHOD

      Added suppress gen_id 119, sig_id 4 for BARE BYTE UNICODE ENCODING but with no effect (restarted snort afther adding the suppress rule)

      Tried to disable the rule from Wan rules > preprocessor.rules, in the snort Alert the disabled rules will appear with a yellow X but snort will block this alert even if is disabled.

      Is there a way to disable all the snort rules ? I only want to use my custom rules.. tnx.

      1 Reply Last reply Reply Quote 0
      • BBcan177
        BBcan177 Moderator last edited by

        The following threads have some more info to help you :

        https://forum.pfsense.org/index.php?topic=87374.msg479725#msg479725

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • G
          godtor last edited by

          Already did that, from there i have the suppress list.. problem is that suppress list not working..

          1 Reply Last reply Reply Quote 0
          • G
            godtor last edited by

            Solved, i was missing the "Choose a suppression or filtering file if desired" option.. my bad sry :)

            1 Reply Last reply Reply Quote 0
            • bmeeks
              bmeeks last edited by

              @godtor:

              Solved, i was missing the "Choose a suppression or filtering file if desired" option.. my bad sry :)

              And after choosing that file and saving the change, remember to restart Snort on that interface.

              Bill

              1 Reply Last reply Reply Quote 0
              • First post
                Last post