Table of Contents

PFSense - Suricata - Pass Lists

IMPORTANT: Passlists should NOT be used.

Realistically, about the only time that you should require a Passlist is if you are running a honeypot host and you actually want bad stuff to find its way to that host.

In that situation, a passlist makes sense.

For about any other case, it does not.

Use custom PASS rules instead if you really need passlist functionality.


Setup a Passlist

Setup an Alias for Custom IP Addresses

Navigate to Firewall → Alias → IP


Setup the Passlist

Navigate to Services > Suricata > Pass Lists.


Enable use of this Passlist

Navigate to Services → Suricata → Interfaces.


Restart

Navigate to Services → Suricata → Interfaces.


References

https://www.cnblogs.com/lsgxeva/p/11392627.html