pfsense:suricata:install_suricata
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
pfsense:suricata:install_suricata [2021/01/22 12:20] – peter | pfsense:suricata:install_suricata [2021/01/22 13:59] (current) – [PFSense - Suricata - Install Suricata] peter | ||
---|---|---|---|
Line 7: | Line 7: | ||
- [[PFSense: | - [[PFSense: | ||
- [[PFSense: | - [[PFSense: | ||
+ | - [[PFSense: | ||
+ | ---- | ||
+ | |||
+ | |||
+ | ==== Created a suppress list ==== | ||
+ | |||
+ | To suppress certain snort and ET signatures since initially there a bunch of False Positives. | ||
+ | |||
+ | This is accomplished under **Services -> Suricata -> Suppress**. | ||
+ | |||
+ | {{: | ||
+ | |||
+ | <WRAP info> | ||
+ | **NOTE: | ||
+ | |||
+ | In order for this specific list to be used: | ||
+ | |||
+ | * Navigate to **Services -> Suricata -> Interfaces**. | ||
+ | * Edit the specific interface; in this example WAN. | ||
+ | * Within **WAN Settings**, go to **Alert Suppression and Filtering** and select this suppresslist. | ||
+ | * Click **Save**. | ||
+ | |||
+ | </ | ||
---- | ---- | ||
+ | ==== Rule categories ==== | ||
+ | |||
+ | Choose what rule categories to enable: | ||
+ | |||
+ | Navigate to **Services -> Suricata -> Interfaces -> WAN Categories**. | ||
+ | |||
+ | ---- | ||
pfsense/suricata/install_suricata.1611318054.txt.gz · Last modified: 2021/01/22 12:20 by peter