Skip to content
Discussion options

You must be logged in to vote

after 23:00 I would like to block any traffic from 192.168.135.144

To clarify, Security Onion is totally passive and so it doesn't actually block any traffic. A BPF will filter the traffic so that it is not seen by a sniffing process like Suricata, Zeek, or Stenographer.

If you want different BPF configurations at different times of day, one option might be to create cron jobs to update the config file.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@ErlindS
Comment options

Answer selected by TOoSmOotH
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants