OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • help with getting rules to block not just Alert
« previous next »
  • Print
Pages: [1]

Author Topic: help with getting rules to block not just Alert  (Read 4386 times)

opnsense-user123

  • Newbie
  • *
  • Posts: 25
  • Karma: 2
    • View Profile
help with getting rules to block not just Alert
« on: December 30, 2017, 06:04:41 pm »
Hello:

I tried to enable some intrusion prevention by following this guide: https://wiki.opnsense.org/manual/how-tos/ips-feodo.html

I believe I followed the steps correctly, including changing the default behavior 'change all alerts to drop actions' which I saved and updated. But when I look at the rules they still show the Action is Alert and under 'Alerts' I saw this which seems to indicate (though I'm not sure) a matched rule caused an alert not a block:

Code: [Select]
2017-12-30T16:22:00.512712+0000 allowed wan [redacted]  65264 69.192.76.62 443 SURICATA STREAM excessive retransmissions
It would be kind of tedius to switch all 3000 rules to block manually. Thanks for any help.
Logged

opnsense-user123

  • Newbie
  • *
  • Posts: 25
  • Karma: 2
    • View Profile
Re: help with getting rules to block not just Alert
« Reply #1 on: December 30, 2017, 06:55:58 pm »
... I kept working on IPS, enabling some Snort rules, and restarted Suricata, and now when I look at the abuse.ch.sslblacklist.rules they are showing DROP. So, it fixed itself or else required a restart of Suricata service.
Logged

dcol

  • Hero Member
  • *****
  • Posts: 635
  • Karma: 51
    • View Profile
Re: help with getting rules to block not just Alert
« Reply #2 on: January 17, 2018, 06:07:50 pm »
Changing all the rules to drop works but it takes a few minutes to propagate. Doesn't seem to have anything to do with restarting the Suricata service, although you have to restart the service to apply the rules.
« Last Edit: January 17, 2018, 06:23:08 pm by dcol »
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • help with getting rules to block not just Alert
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2