OPNsense Forum

English Forums => Documentation and Translation => Topic started by: DoubleJ on October 03, 2015, 02:07:06 pm

Title: [SOLVED] Intrusion detection documentation
Post by: DoubleJ on October 03, 2015, 02:07:06 pm
Does anyone know where to find any information, documentation or help files on opnsense's intrusion detection?

thnx in advance
Title: Re: Intrusion detection documentation
Post by: franco on October 11, 2015, 01:46:55 pm
Hi there,

the feature is "quite" new and was rebuilt from the ground up, we don't have more documentation than what is scattered around the forum I fear. Are you looking for a specific piece of info or just a general introduction?


Cheers,
Franco
Title: Re: Intrusion detection documentation
Post by: DoubleJ on October 26, 2015, 05:36:11 pm
I'm interested introduction. What is the functionality of the service? does it block or only registers? What are rulesets? what is the diff with the rules tab? what does every rule or ruleset do (criteria?) ?

I want to understand the service; decide whether it is useful in my situation and if so, what config options are of interest.
Title: Re: Intrusion detection documentation
Post by: franco on October 27, 2015, 11:19:58 am
Jos is working on new material, I'll ask if he has this planned already. Thanks for your feedback. :)
Title: Re: Intrusion detection documentation
Post by: franco on October 28, 2015, 10:43:26 pm
This is what I could gather from a rather busy Jos:

Quote
No I don’t have anything for IDS, but the current IDS is straight forward just enable a ruleset and then you can apply individual rules or keep the defaults. Currently it only generates alerts, visible in the Alert tab.. that is it.. testing it will take 5-10 minutes ;-)

For 16.1 it will become a little bit more difficult as then you should be able to change the behavior from alert to block.
Title: Re: Intrusion detection documentation
Post by: DoubleJ on October 31, 2015, 05:41:07 pm
Ok thnx, I'll play around with it.
Title: Re: Intrusion detection documentation
Post by: jschellevis on February 24, 2016, 01:42:39 pm
Documentation has been updated for many topics including the IDP and inline IPS solution.

See: https://docs.opnsense.org/manual/ips.html (https://docs.opnsense.org/manual/ips.html)