Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata and/or Snort categories on schedule

    Scheduled Pinned Locked Moved IDS/IPS
    4 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lokapal
      last edited by

      Hello, friendly firewallers and intruder seekers!  :D

      How can I turn on/off some Snort/Suricata categories on schedule, I wonder? The purpose is quite obvious - to restrict P2P and online gaming during worktime. Right now I didn't found anything concerning schedule inside Suricata and I don't remember anything concerning it in Snort. I have only relatively stupid idea to replace the whole pfsense XML config file by cron job and restart PFsense…

      1 Reply Last reply Reply Quote 1
      • bmeeksB
        bmeeks
        last edited by

        @lokapal:

        Hello, friendly firewallers and intruder seekers!  :D

        How can I turn on/off some Snort/Suricata categories on schedule, I wonder? The purpose is quite obvious - to restrict P2P and online gaming during worktime. Right now I didn't found anything concerning schedule inside Suricata and I don't remember anything concerning it in Snort. I have only relatively stupid idea to replace the whole pfsense XML config file by cron job and restart PFsense…

        Neither package works that way and such an option is not currently available.  If you want to restrict P2P and online gaming, why not just enable those rules and leave them enabled in Suricata?  For a business environment, when would it ever be acceptable to enable P2P (can anyone say potential copyright violations?) and online gaming?

        Bill

        1 Reply Last reply Reply Quote 0
        • L
          lokapal
          last edited by

          I guess real busyness environments will use Cisco solutions anyway in most cases  ::)
          My case is much more similar to educational organization campus. Do you like to explain to x00 linuxoids why they can't download at lightspeed their favorites ubuntus, debians, gentoos and scientific linuxes via bittorrent at least after worktime? 8) The same thing with online gaming…  ;D

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks
            last edited by

            @lokapal:

            I guess real busyness environments will use Cisco solutions anyway in most cases  ::)
            My case is much more similar to educational organization campus. Do you like to explain to x00 linuxoids why they can't download at lightspeed their favorites ubuntus, debians, gentoos and scientific linuxes via bittorrent at least after worktime? 8) The same thing with online gaming…  ;D

            Why don't you create a Guest Wireless Network and give greater freedom there, but restrict its access to your school LAN?  Do you let the folks install and run P2P clients and games on your business or school machines?  If so, I would say that is a bad policy.

            At any rate, the answer to your original question is that currently neither IDS/IPS package offers such scheduling (it is not present in the underlying binaries anyway), and such a feature is not currently on the long-term planning radar.  You can schedule firewall rules within pfSense itself, but using those will be problematic because you would need to capture all the IP addresses of the potential P2P and gaming sites.  That is hard because the IPs can change frequently.

            Bill

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.