From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael Tremer To: development@lists.ipfire.org Subject: Re: Suppress Feature Date: Wed, 24 Feb 2021 11:58:52 +0000 Message-ID: In-Reply-To: <88B683D4-42A1-40D8-A143-5DE9A72F32E6@yahoo.com> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============6733227203629534046==" List-Id: --===============6733227203629534046== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Ah okay. IPFire currently does not provide that functionality over the UI. > On 24 Feb 2021, at 11:49, Reza Fathi wrote: >=20 > =EF=BB=BFHello, Michael, >=20 > Yes i know the whitelist but if you see the link i provided you can suppres= s based on a single rule for any source or destination ip. But in whitelist i= f I add a host I won=E2=80=99t get any alert anymore. >=20 > Regards, > Reza. >=20 > On Feb 24, 2021, at 14:39, Michael Tremer wro= te: >=20 > =EF=BB=BFHello Reza, >=20 > IPFire has a whitelist feature where you can add hosts so that they won=E2= =80=99t be blocked at all. >=20 > Is it this what you are looking for? >=20 > -Michael >=20 >> On 23 Feb 2021, at 21:59, Reza Fathi wrote: >>=20 >> =EF=BB=BF >> =EF=BB=BFDear madam/sir, >>=20 >> As you might know there is a feature in pfsense called suppress list where= you can add source or destination ip addresses along with a rule causing the= alert to bypass it. But that is not available in ipfire. So is there any way= so I can add suppress list on suricata by hand? Would you please add this fe= ature in ipfire?. Thanks. >>=20 >> https://pfsense-docs.readthedocs.io/en/latest/ids-ips/snort-suppress-list.= html >>=20 >>=20 >> Regards, >> Reza. >=20 >=20 --===============6733227203629534046==--