Interface List

Opening the Interface Configuration tab displays a list of all defined instances of Snort 3. Each instance can monitor one or more interfaces.

Add New Interface

To add a new Snort instance, click nexus-add-item in the toolbox. This opens the Interface Settings window to create a new instance.

List Entries

Each entry in the list on this tab contains several fields and action icons, described here.

ID

The unique identifier Netgate Nexus generated and assigned to the instance.

Interfaces

The interface(s) this instance is monitoring for network traffic.

Description

The text description of this instance.

Status

Indicates the current state of the instance and has controls for the service.

Status

Prints the current state of the instance, e.g. “Running”, “Stopped”.

nexus-stop Stop

Click to stop this instance.

nexus-play Start

Click to start this instance.

nexus-restart Restart

Click to stop and then start this instance.

Tip

Individual instances can also be controlled from Status > Services.

Rulesets

A list of Rulesets this instance is using.

Action Icons

This area contains icons to perform actions on this instance.

nexus-list-detail Show Alerts

Click to Show Alerts generated by this instance.

nexus-ban Show Blocked Hosts

Click to Show Blocked Hosts due to alerts on this instance.

nexus-edit Edit

Click to edit the settings for this instance.

nexus-refresh Reload

Click to reload the configuration of this instance without restarting the process.

nexus-trash Delete

Click to remove this instance.

Show Alerts

Clicking nexus-list-detail on the row of a Snort instance displays the alerts generated by the instance.

The Alerts list contains a table with entries that have the following columns:

Time

Timestamp when Snort generated the alert.

Priority

The severity level set by the rule that generated the alert. Lower numbers are more severe, with 1 being the most severe.

Class

Classification type of the rule that generated the alert, if known.

GID

Generator ID of the Snort rule that generated the alert.

SID

Signature ID of the Snort rule that generated the alert.

Click nexus-add-solid to Add this SID to a suppress list.

Click nexus-remove-solid to disable and remove this rule from the ruleset.

Source

The Source IP address of traffic that triggered the alert.

Click nexus-add-sep-list suppress to suppress alerts for this rule from this source address.

SPort

The Source port of traffic that triggered the alert.

Destination

The Destination IP address of traffic that triggered the alert.

Click nexus-add-sep-list suppress to suppress alerts for this rule from this destination address.

DPort

The Destination port of traffic that triggered the alert.

Description

The description of the rule that generated the alert.

Show Blocked Hosts

Clicking nexus-ban on the row of a Snort instance displays the hosts blocked due to alerts generated by the instance. All traffic to and from these hosts is blocked by the packet filter.

The table contains a list of IP addresses, one per line.

Click nexus-trash on a row to clear the block for that host.

Click Refresh to reload the list of blocked hosts.

Click Clear to remove all entries from the blocked hosts table.