OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • 18.7.10 Suricata 4.1.2 GeoIP
« previous next »
  • Print
Pages: [1]

Author Topic: 18.7.10 Suricata 4.1.2 GeoIP  (Read 5233 times)

MakesSense

  • Newbie
  • *
  • Posts: 17
  • Karma: 2
    • View Profile
18.7.10 Suricata 4.1.2 GeoIP
« on: January 13, 2019, 10:25:03 pm »
Hi

Anyone else having problems with geoip rules in Suricata 4.2.1? Every time I try to load a rule with geoip Suricata throws an error...
Logged

The_Sage

  • Newbie
  • *
  • Posts: 48
  • Karma: 6
    • View Profile
Re: 18.7.10 Suricata 4.1.2 GeoIP
« Reply #1 on: January 14, 2019, 08:31:43 am »
GEO Ip has been made redundant in Suricata.

Use Firewall alias, Geo IP instead. (cant find link)
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13936
  • Karma: 1208
    • View Profile
Re: 18.7.10 Suricata 4.1.2 GeoIP
« Reply #2 on: January 14, 2019, 08:51:18 am »
This seems to be a problematic complication with the GeoIP database provider not publishing its database (in the old format) anymore:

https://svnweb.freebsd.org/ports/head/UPDATING?r1=490211&r2=490210&pathrev=490211

19.1 removes the GeoIP database from intrusion prevention since it can't be used anymore and we'll see if this also impacts firewall aliases.

But it's correct that firewall aliases is the way to go whether or not we have to fix them to stay operational.


Cheers,
Franco

Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2108
  • Karma: 94
    • View Profile
Re: 18.7.10 Suricata 4.1.2 GeoIP
« Reply #3 on: January 14, 2019, 08:53:13 am »
I have geoblocking activated in suricata as well, might this be related to the "loosing interface" issue with 18.7.10?
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

MakesSense

  • Newbie
  • *
  • Posts: 17
  • Karma: 2
    • View Profile
Re: 18.7.10 Suricata 4.1.2 GeoIP
« Reply #4 on: January 14, 2019, 09:21:20 am »
Thanks for the info! I will use firewall for geoblock then:-)

Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13936
  • Karma: 1208
    • View Profile
Re: 18.7.10 Suricata 4.1.2 GeoIP
« Reply #5 on: January 14, 2019, 10:18:44 am »
@chemlud Could be, but entirely unsure.

We checked the firewall aliases GeoIP and it uses the version 2 database so we're good on this front. Best to migrate now... :)


Cheers,
Franco
Logged

MakesSense

  • Newbie
  • *
  • Posts: 17
  • Karma: 2
    • View Profile
Re: 18.7.10 Suricata 4.1.2 GeoIP
« Reply #6 on: January 14, 2019, 10:41:54 am »
Quote from: franco on January 14, 2019, 10:18:44 am
We checked the firewall aliases GeoIP and it uses the version 2 database so we're good on this front. Best to migrate now... :)


Cheers,
Franco

Super, thanks franco! Migration done! :)
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2108
  • Karma: 94
    • View Profile
Re: 18.7.10 Suricata 4.1.2 GeoIP
« Reply #7 on: January 14, 2019, 10:58:06 am »
Any hint on HOW-TO move? :-)
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13936
  • Karma: 1208
    • View Profile
Re: 18.7.10 Suricata 4.1.2 GeoIP
« Reply #8 on: January 14, 2019, 11:41:22 am »
Yes and no, there is a small introduction at https://docs.opnsense.org/manual/aliases.html#aliases-geoip although it displays the older GeoIP selector. It also later explains aliases in rules.


Cheers,
Franco
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2108
  • Karma: 94
    • View Profile
Re: 18.7.10 Suricata 4.1.2 GeoIP
« Reply #9 on: January 14, 2019, 12:06:43 pm »
OK, so I created an Alias with the respective countries and a block rule really high up with "Destination" -> alias with countries for geoblocking. Correct? :-)
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13936
  • Karma: 1208
    • View Profile
Re: 18.7.10 Suricata 4.1.2 GeoIP
« Reply #10 on: January 14, 2019, 03:13:27 pm »
Yes, you want these in your LAN (or OPT) interfaces high up.

When using floating rules make sure to select "Quick" option as otherwise other rules could overwrite the decision.


Cheers,
Franco
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • 18.7.10 Suricata 4.1.2 GeoIP
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2