NethServer Version: 7.7.1908
Module: The IPS (Intrusion Prevention System) module 1.3.1
I have installed the above mentioned Module and enable the block function on the
Dns (ET-emerging-dns) section.
I have noticed alot “false positives” are being blocked now, Is there a way to whitelist in this module?
mrmarkuz
(Markus Neuberger)
April 2, 2020, 11:12pm
2
You may just disable the affected rule in the category/section or do a whitelisting:
HI all,
I’m looking for a way to disable one suricata rule by its SID without disabling whole category. Is it enough to put the SID taken from evebox in the file /etc/pulledpork/disablesid.conf followed by a signal-event nethserver-suricata-update and systemctl restart suricata ?
What can I do if I would only whitelist an IP address to have it not filtered for any rule?
BR Stefano
Thank you so much
This worked.
No I am trying to find a way to “whitelist” certain things that are being blocked.
I tried editing the enablesid.conf file with a SID but it does not help.
mrmarkuz
(Markus Neuberger)
April 8, 2020, 8:40pm
4
In enablesid.conf are only the rules to alert instead of block. And dropsid.conf (the blocked ones) takes precedence over enabledsid.conf so it doesn’t work anyway.
I assume you have to use disablesid.conf to whitelist an sid.