Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
suricata blocklist
« previous
next »
Print
Pages: [
1
]
Author
Topic: suricata blocklist (Read 1854 times)
tomsch
Newbie
Posts: 9
Karma: 0
suricata blocklist
«
on:
July 11, 2022, 01:19:57 pm »
hi,
is it possible to add the attackers IP (suricatas droped/blocked attacks) to a IP blocklist and block it before entering IPS ?
most of the time the same attacks from same ip happens every day and i want to pre block it per ip.
i know pfsense can do this, but i cant figure out to set it up on opnsense
thanks
tom
Logged
abulafia
Full Member
Posts: 156
Karma: 8
Re: suricata blocklist
«
Reply #1 on:
July 12, 2022, 08:36:43 am »
Not what you are looking for exactly, but you can lock.all.known IP Blocklists via a firewall URL alias. Requires less performance than IDS.
Logged
tomsch
Newbie
Posts: 9
Karma: 0
Re: suricata blocklist
«
Reply #2 on:
July 12, 2022, 11:34:36 am »
yeah i already know that thx.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
suricata blocklist