OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: nhk on April 02, 2026, 11:18:59 AM

Title: Problem with IPS/IDS Divert Mode
Post by: nhk on April 02, 2026, 11:18:59 AM
Hello,

I am using IDS/IPS in divert mode. It works correctly while the service is running. However, when I stop the IDS/IPS service, the rules no longer work. For example, I am not able to SSH to the server even though it should be allow by my rules.

Does it a bug?
Title: Re: Problem with IPS/IDS Divert Mode
Post by: Monviech (Cedrik) on April 02, 2026, 12:04:40 PM
Its not a bug, you divert the paket decisions to a different service, if its not running nobody can decide, there is no fallback for obvious reasons (what if somebody maliciously stops your IDS service for example)
Title: Re: Problem with IPS/IDS Divert Mode
Post by: Patrick M. Hausen on April 02, 2026, 12:11:02 PM
Since diverting to IDS is handled by explicit firewall rules you could exempt local management traffic from the IDS.
Title: Re: Problem with IPS/IDS Divert Mode
Post by: nhk on April 03, 2026, 12:11:22 AM
Quote from: Monviech (Cedrik) on April 02, 2026, 12:04:40 PMIts not a bug, you divert the paket decisions to a different service, if its not running nobody can decide, there is no fallback for obvious reasons (what if somebody maliciously stops your IDS service for example)

oh, I get it but I think it will cause some impact if we need maintenance Suricata such as restart it.
Title: Re: Problem with IPS/IDS Divert Mode
Post by: nhk on April 03, 2026, 12:15:31 AM
Quote from: Patrick M. Hausen on April 02, 2026, 12:11:02 PMSince diverting to IDS is handled by explicit firewall rules you could exempt local management traffic from the IDS.

OK, Thank you for advice. I am planning to enable IPS for all rules.