OPNsense Forum

English Forums => 25.7 Series => Topic started by: wuwzy on August 01, 2025, 06:47:46 AM

Title: The blocked IP address in the intrusion detection system has now been turned int
Post by: wuwzy on August 01, 2025, 06:47:46 AM
I've revisited a previous issue: in intrusion detection, users can specify a specific IP address range to block, but the result is a warning, not a block. This allows attackers scanning for the IP address range to access it and carry out their malicious activities. I wonder how many more times this problem will recur.
Title: Re: The blocked IP address in the intrusion detection system has now been turned int
Post by: sopex8260 on August 01, 2025, 11:24:29 AM
A) Why does your firewall allow out -> in connections?
B) Blocking IP ranges has no reason to happen in intrusion detection, create a firewall rule
C) You created a custom rule and at action chose "Drop" but it instead "Alerts"?