It still works
In general is there an allow list which prevents such issues?
Currently Surricata is using the IPS mode already.
2001569 blocked WAN_500 192.168.101.11 52389 192.168.10.104 445 ET SCAN Behavioral Unusual Port 445 traffic Potential Scan or Infection
But SMB access itself works. I can open any SMB shares without any problems
alert tcp $HOME_NET any -> any 445 (msg:"ET SCAN Behavioral Unusual Port 445 traffic Potential Scan or Infection"; flow:to_server; flags: S,12; threshold: type both, track by_src, count 70 , seconds 60; reference:url,doc.emergingthreats.net/2001569; classtype:misc-activity; sid:2001569; rev:15; metadata:created_at 2010_07_30, former_category SCAN, updated_at 2017_05_11;)
Surricata still denied traffic.
Is this also an expected behaviour?