OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: hushcoden on July 15, 2020, 01:08:34 PM

Title: Setting IDS/IPS
Post by: hushcoden on July 15, 2020, 01:08:34 PM
On the tab 'Settings' -> 'advanced mode' I see you can enter your home networks details: it's currently blank, so should I enter the IP addresses of my local devices, i.e. something like 192.168.0.0/24 or 192.168.0.0/16 ?

Could someone please explain pros and cons of leaving that field empty ?

Tia.
Title: Re: Setting IDS/IPS
Post by: mimugmail on July 15, 2020, 01:50:28 PM
Per default all private IPs are in this field if you havent cleared it.
If IPS listend on LAN you should add your LAN network there, if it listens on WAN then add your WAN IP
Title: Re: Setting IDS/IPS
Post by: hushcoden on July 15, 2020, 02:21:33 PM
Quote from: mimugmail on July 15, 2020, 01:50:28 PM
Per default all private IPs are in this field if you havent cleared it.
Ah yes, I must have delete those entries...  ::)

So, if it's just LAN then I will add the LAN address, i.e. 192.168.0.0/24

Or should I cover the all network range by entering 192.168.0.0/16 instead ?
Title: Re: Setting IDS/IPS
Post by: FullyBorked on July 15, 2020, 03:03:32 PM
Quote from: hushcoden on July 15, 2020, 02:21:33 PM
Quote from: mimugmail on July 15, 2020, 01:50:28 PM
Per default all private IPs are in this field if you havent cleared it.
Ah yes, I must have delete those entries...  ::)

So, if it's just LAN then I will add the LAN address, i.e. 192.168.0.0/24

Or should I cover the all network range by entering 192.168.0.0/16 instead ?

Yes you want to add all local subnets to that field.  To answer your question if you have a 192.168.0.0/24 and a 192.168.1.0/24 etc you can add 192.168.0.0/16 to cover that entire range.