OPNsense Forum

English Forums => General Discussion => Topic started by: crissi on December 26, 2021, 02:47:26 pm

Title: Maltrail on Opnsense
Post by: crissi on December 26, 2021, 02:47:26 pm
Hello,

i installed Maltrail Server / Sensor on OPNsense 21.7.7 . Under Maltrail - Sensor - Remote Port Help, if i left the setting empty (as Sensor / Server) on the same Device, i get the error when saving "Field remoteport is required"


The Auto Generated Alias BlocklistMaltrail , and added to a Rule from my side. But the Content in the Alias is empty, nothing loaded, even after reapplying the settings.

Also, in the Gui Settings, is there not yet the possibility to change Gui Access Port Protocol to https?

Any Idea how to Fix this?

Is Maltrail in general Production ready?

Thx!
Title: Re: Maltrail on Opnsense
Post by: BernhardMM on January 25, 2022, 01:33:25 pm
Maltrail is at 0.41 now (https://github.com/stamparm/maltrail/releases) and OPNSense packages an older version (1.8 correlates to?), apparantly - there is a small problem with detection of it's own access/location of blacklist, see https://github.com/stamparm/maltrail/issues/19044 - updating it would likely help.
Title: Re: Maltrail on Opnsense
Post by: mimugmail on January 25, 2022, 01:39:43 pm
Maybe you need to remove the trails manually and restart.
You can see the current installed version in System : Firmware : Packages
Title: Re: Maltrail on Opnsense
Post by: skyfighter on April 15, 2022, 10:44:16 am
Will there be an update for Maltrail plugin on opnsense in the next time?
Title: Re: Maltrail on Opnsense
Post by: mimugmail on April 15, 2022, 09:32:14 pm
No need for this to update the plugin. The pkg itself is enough
Title: Re: Maltrail on Opnsense
Post by: defaultuserfoo on May 22, 2022, 06:20:09 pm
Will maltrail do anything other than providing statistics, like block access to malware sites?
Title: Re: Maltrail on Opnsense
Post by: mimugmail on May 22, 2022, 08:17:57 pm
There is an option to add those hosts to an external alias
Title: Re: Maltrail on Opnsense
Post by: defaultuserfoo on May 22, 2022, 08:47:00 pm
Hmmm ...

You mean "Adds firewall alias "BlocklistMaltrail" referencing Maltrail's "/fail2ban" IP list. You can use this alias to block IPs that Maltrail detected as malicious."?

Ok I added a rule to block all IPv4 and IPv6 traffic coming from the alias to the WAN interface which maltrail is listening on.

Where/how do I see which addresses are on the list and how would I remove addresses if I need to?

Can/should I make a rule that rejects all traffic to the alias from any interface that allows internet access without making such a rule for each interface?
Title: Re: Maltrail on Opnsense
Post by: mimugmail on May 22, 2022, 08:51:24 pm
Firewall : Diagnostics : Alias there you can check the content
Title: Re: Maltrail on Opnsense
Post by: defaultuserfoo on May 23, 2022, 01:00:14 am
Cool, thank you :)
Title: Re: Maltrail on Opnsense
Post by: sanscorp on June 20, 2022, 09:04:16 am
Can someone please explain how to auto block the maltrail detections?
As an absolute beginner it is hard to find some info on this subject.

Few questions:
Is an alias just a name for a group to keep it manageable?
I do see an auto generated alias named "BlocklistMaltrail" but it does not contain any addresses.

It would be nice to only auto block medium and high security threads.
Running OPNsense version 22.1.8_1 and Mailtrail version 1.8

Thanks!
Title: Re: Maltrail on Opnsense
Post by: meelokun on September 26, 2022, 08:58:32 am
Bump - I too have the same questions.

Can someone please explain how to auto block the maltrail detections?
As an absolute beginner it is hard to find some info on this subject.

Few questions:
Is an alias just a name for a group to keep it manageable?
I do see an auto generated alias named "BlocklistMaltrail" but it does not contain any addresses.

It would be nice to only auto block medium and high security threads.
Running OPNsense version 22.1.8_1 and Mailtrail version 1.8

Thanks!
Title: Re: Maltrail on Opnsense
Post by: mimugmail on September 26, 2022, 09:37:03 am
If you enable the feature you'll have an Alias with type "External" which you can use in your filter rules :)
Title: Re: Maltrail on Opnsense
Post by: meelokun on September 26, 2022, 04:23:10 pm
When enabling "Add Blocklist Alias", I do see an auto generated alias named "BlocklistMaltrail", however it's type was instead "URL Table (IPs)", and when I visit "Firewall -> Diagnostics -> Aliases", it did not contain any addresses, despite maltrail already accumulating well over 20 malware threats of high severity.

What's gone wrong?

If you enable the feature you'll have an Alias with type "External" which you can use in your filter rules :)
Title: Re: Maltrail on Opnsense
Post by: virtualdimension on March 15, 2023, 02:31:52 am
I always have 0 lines of Maltrail/Fail2ban. Why don't download any lists?
Title: Re: Maltrail on Opnsense
Post by: ARF on July 02, 2023, 02:20:55 am
sorry double post
Title: Re: Maltrail on Opnsense
Post by: ARF on July 02, 2023, 02:21:46 am
Is there any option to add custom options in the maltrail.conf without the GUI or reboot overriding
Title: Re: Maltrail on Opnsense
Post by: mimugmail on July 02, 2023, 12:28:57 pm
No, why not using syslog?
Title: Re: Maltrail on Opnsense
Post by: ARF on July 02, 2023, 01:53:50 pm
Nothing just wanted to know, had an additional hard drive wanted to set log files to