Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata turn on/off blockoffenders through command line

    Scheduled Pinned Locked Moved IDS/IPS
    4 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mcentirefj
      last edited by

      Hi all,

      I'm trying to set a cron job to turn off and on blocking at certain times of the day, but I can't for the life of me find a command to do this so that I can plug it into cron.

      Does anyone else already know of a way to do this?

      1 Reply Last reply Reply Quote 0
      • bmeeksB Online
        bmeeks
        last edited by

        There is no functionality included within the package to do this.  Why would you want to turn off the protection anyway?  If you are having issues with false positives, fix those instead of turning off all protection.

        Bill

        1 Reply Last reply Reply Quote 0
        • M Offline
          mcentirefj
          last edited by

          We haven't implemented the IPS in production yet. The thinking was in the beginning stages of implementation we would only block hosts during working hours so that we can handle any false positives/blocks while we are on the clock, and disable blocking so issues don't crop up when we've all gone home for the day. If it's not possible then we'll just have to deal with it I guess.

          1 Reply Last reply Reply Quote 0
          • BBcan177B Offline
            BBcan177 Moderator
            last edited by

            Start to use the IDS in non-blocking mode for a couple weeks. This will give you time to fine-tune the rulesets according to the network characteristics.

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.