pfsense:suricata:install_suricata:create_suppress_lists
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
pfsense:suricata:install_suricata:create_suppress_lists [2021/01/22 12:19] – peter | pfsense:suricata:install_suricata:create_suppress_lists [2021/01/22 13:55] (current) – [Pass List] peter | ||
---|---|---|---|
Line 1: | Line 1: | ||
====== PFSense - Suricata - Install Suricata - Create Suppress Lists ====== | ====== PFSense - Suricata - Install Suricata - Create Suppress Lists ====== | ||
+ | |||
+ | To suppress certain snort and ET signatures since initially there a bunch of False Positives. | ||
I prefer having different Suppress lists for each interface. | I prefer having different Suppress lists for each interface. | ||
Line 60: | Line 62: | ||
---- | ---- | ||
- | Return to [[PFSense: | + | Return to [[PFSense: |
---- | ---- | ||
+ | |||
+ | ===== Pass List ===== | ||
+ | |||
+ | <WRAP alert> | ||
+ | **ALERT: | ||
+ | |||
+ | At **Services -> Suricata -> Pass List**. | ||
+ | |||
+ | Realistically, | ||
+ | |||
+ | In that situation, a passlist makes sense. | ||
+ | |||
+ | For about any other case, it does not. | ||
+ | |||
+ | Use custom PASS rules instead if you really need passlist functionality. | ||
+ | |||
+ | </ | ||
+ | |||
+ | |||
pfsense/suricata/install_suricata/create_suppress_lists.1611317982.txt.gz · Last modified: 2021/01/22 12:19 by peter