OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: jmodlin on March 04, 2024, 06:42:58 PM

Title: Suricata blocking Microsoft Teams
Post by: jmodlin on March 04, 2024, 06:42:58 PM
After upgrading to 24.1.2_1 Suricata has begun blocking some MS Teams traffic, is there a way, without turning IPS/IDS off to add an allow rule for their traffic?

Any assistance is greatly appreciated..
Title: Re: Suricata blocking Microsoft Teams
Post by: xpendable on March 08, 2024, 10:45:18 PM
I use MS Teams all the time and have no issues. If you are usign the emerging-chat rules, you may want to disable them instead. However you can always disable the specific rules that are blocking the traffic instead. Some troubleshooting would be involved in monitoring the alerts to identify which rules are blocking the traffic though.
Title: Re: Suricata blocking Microsoft Teams
Post by: mimugmail on March 09, 2024, 09:39:33 AM
Quote from: jmodlin on March 04, 2024, 06:42:58 PM
After upgrading to 24.1.2_1 Suricata has begun blocking some MS Teams traffic, is there a way, without turning IPS/IDS off to add an allow rule for their traffic?

Any assistance is greatly appreciated..

Also witj 24.1.3?
Title: Re: Suricata blocking Microsoft Teams
Post by: jmodlin on March 12, 2024, 09:56:34 PM
It was fixed in 24.1.3_1
Title: Re: Suricata blocking Microsoft Teams
Post by: Enoch58 on April 06, 2024, 11:58:34 AM
I frequently utilize MS Teams without encountering any problems. If you're experiencing issues due to emerging-chat rules, consider disabling them. Alternatively, you can plnkgame (https://plnkgame.com) individually deactivate the specific rules causing the blockage. Troubleshooting would entail monitoring alerts to pinpoint which rules are causing the traffic obstruction.