pfsense:suricata:install_suricata:create_suppress_lists
Differences
This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
pfsense:suricata:install_suricata:create_suppress_lists [2021/01/15 14:18] – created peter | pfsense:suricata:install_suricata:create_suppress_lists [2021/01/22 13:55] (current) – [Pass List] peter | ||
---|---|---|---|
Line 1: | Line 1: | ||
====== PFSense - Suricata - Install Suricata - Create Suppress Lists ====== | ====== PFSense - Suricata - Install Suricata - Create Suppress Lists ====== | ||
+ | |||
+ | To suppress certain snort and ET signatures since initially there a bunch of False Positives. | ||
I prefer having different Suppress lists for each interface. | I prefer having different Suppress lists for each interface. | ||
Line 12: | Line 14: | ||
* Name: **WANSuppressList**. | * Name: **WANSuppressList**. | ||
* Description: | * Description: | ||
+ | * Click **Save**. | ||
---- | ---- | ||
Line 22: | Line 25: | ||
* Name: **LANSuppressList**. | * Name: **LANSuppressList**. | ||
* Description: | * Description: | ||
+ | * Click **Save**. | ||
---- | ---- | ||
Line 32: | Line 36: | ||
* Name: **ClearSuppressList**. | * Name: **ClearSuppressList**. | ||
* Description: | * Description: | ||
+ | * Click **Save**. | ||
---- | ---- | ||
Line 42: | Line 47: | ||
* Name: **IOTSuppressList**. | * Name: **IOTSuppressList**. | ||
* Description: | * Description: | ||
+ | * Click **Save**. | ||
---- | ---- | ||
Line 52: | Line 58: | ||
* Name: **GuestSuppressList**. | * Name: **GuestSuppressList**. | ||
* Description: | * Description: | ||
+ | * Click **Save**. | ||
---- | ---- | ||
+ | |||
+ | Return to [[PFSense: | ||
+ | |||
+ | ---- | ||
+ | |||
+ | ===== Pass List ===== | ||
+ | |||
+ | <WRAP alert> | ||
+ | **ALERT: | ||
+ | |||
+ | At **Services -> Suricata -> Pass List**. | ||
+ | |||
+ | Realistically, | ||
+ | |||
+ | In that situation, a passlist makes sense. | ||
+ | |||
+ | For about any other case, it does not. | ||
+ | |||
+ | Use custom PASS rules instead if you really need passlist functionality. | ||
+ | |||
+ | </ | ||
+ | |||
+ | |||
+ |
pfsense/suricata/install_suricata/create_suppress_lists.1610720326.txt.gz · Last modified: 2021/01/15 14:18 by peter