OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: tomsch on July 11, 2022, 01:19:57 PM

Title: suricata blocklist
Post by: tomsch on July 11, 2022, 01:19:57 PM
hi,

is it possible to add the attackers IP (suricatas droped/blocked attacks) to a IP blocklist and block it before entering IPS ?

most of the time the same attacks from same ip happens every day and i want to pre block it per ip.

i know pfsense can do this, but i cant figure out to set it up on opnsense

thanks
tom
Title: Re: suricata blocklist
Post by: abulafia on July 12, 2022, 08:36:43 AM
Not what you are looking for exactly, but you can lock.all.known IP Blocklists via a firewall URL alias. Requires less performance than IDS.
Title: Re: suricata blocklist
Post by: tomsch on July 12, 2022, 11:34:36 AM
yeah i already know that thx.