OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: Meg on February 28, 2025, 12:21:58 AM

Title: Suricata IPS Unblocking a blocked Ip address
Post by: Meg on February 28, 2025, 12:21:58 AM
I am new to using suricata and was wondering when a rule blocks an Ip address how long is it blocked for and can I change the length of time a rule blocks an ip address. Also how would I unblock an ip that was blocked that is a false positive.
Title: Re: Suricata IPS Unblocking a blocked Ip address
Post by: someone on March 16, 2025, 02:51:57 AM
The length of time is set in the rule if it isnt a permanent block
To change block time you have to change it in the rule on your system, be aware it resets when rules are downloaded again
On your system get the rule, change it, put it back via sftp
Never heard of or seen a false positive
Rules are set to trigger, it isnt false
Would need more information on that
Title: Re: Suricata IPS Unblocking a blocked Ip address
Post by: Meg on March 16, 2025, 06:08:27 PM
Thanks for the reply. I can see that now. About the false positives. I have suricata monitoring the wan with zenarmor on the lan. I have read the there are a lot of false positives from noise" that firewall rules are likely to drop anyway.