Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - shred

#16
Good afternoon,

I'm in the market to purchase some hardware to install a firewall such as OPNsense. I've spent several hours over the past few days messing with pfSense, OPNsense and SophosXG on VirtualBox to see which one I'd like to go with. So far I'm leaning towards OPNsense based on a number of different reasons but one thing I'm trying to understand is the Intrusion Detection. I've set it up the Intrusion Detection and downloaded/enabled the 'OPNsense/test rules' to make sure it works when I access http://www.eicar.org/download/eicar.com.txt and sure enough, I see it in the Alerts (this test method is great by the way and is probably worth adding into the User Guide... only discovered it by searching/reading the forums). After that, I started downloading/enabling several other ET open rules as well but when I view the 'Rules' tab, I'm a bit confused as to how each rule becomes enabled/disabled. I assumed that if I enabled the entire rule set from the 'Download' tab (i.e. ET open/malware), that it would enable all of the corresponding rules associated with it in the 'Rules' tab. However, I've noticed when I disable certain rule sets, the corresponding rules are still enabled. The opposite is true as well where I enable a rule set but the specific rules are not enabled. Hopefully that makes sense but I'm just wondering what I'm missing here...

Edit: As an example, I selected all of the rule sets under 'Download' and click 'Disable selected'. All of them are showing as being disabled (X under every rule set in the Enabled column). However, under the 'Rules' tab, I'm still seeing specific rules enabled (box is checked in the Info/Enabled column) and I'm seeing new alerts show up. Pictures attached.

Second question while I'm on this topic - One thing I liked about pfSense was the ability to suppress or disable the rule from the Alerts view. Is there any way to do this in OPNsense? When I click the info button, the only option I see that is close to what I'm trying to do is the 'Alert action/sid' drop down box that only lets me switch between Alert and Drop.

Anyways, thanks for everyone that is a part of this OPNsense platform and the work you've put in. It's definitely looking like the platform I'm going to end up going with.
#17
Hardware and Performance / Re: qotom i5-5250U
October 30, 2017, 06:46:06 PM
Quote from: remigius on September 08, 2017, 10:26:23 AM
Hoi,

I got mine from aliexpress and it shipped very quickly. On the description of the one I ordered, it was declared that WiFi is not supported under pfSense (which I unfortunately only discovered after I got the box here - but the proce difference is not big anyway).

https://www.aliexpress.com/item/Mini-PC-4-Ethernet-Lan-with-Core-i5-Pfsense-Firewall-Mini-Computer-Fanless-PC-Server/32817388248.html

Cheers, Remi.

Is there any difference between that one and this one?

https://www.aliexpress.com/item/QOTOM-4-LAN-Mini-PC-with-Core-i3-4005U-i5-5250U-processor-and-4-Gigabit-NIC/32812678037.html?spm=2114.search0104.3.1.836tN9&ws_ab_test=searchweb0_0,searchweb201602_3_10152_10065_10151_10130_10068_10344_5620015_10345_10547_10342_10546_10343_10340_10341_10548_10545_10541_10307_5640015_10060_10155_10154_10056_10055_10539_10538_5370015_10537_10536_10059_10534_10533_100031_10103_10102_10142_10107_10324_10325_10084_10083_10178_10312_10313_10314_10073_5630015_5720015,searchweb201603_2,ppcSwitch_5&btsid=c6109212-57ac-40af-971c-8aff3fc5e393&algo_expid=1f6400de-07b4-4a70-9095-0e4f0c341a62-0&algo_pvid=1f6400de-07b4-4a70-9095-0e4f0c341a62

Same model number, same processor and when configured with the same specs (4GB RAM, 32GB SSD), the link you posted is $5 cheaper and it's from Aliexpress as well...

Edit: And of course, there's even another page with the same exact model number, specs, etc. but a different price:

https://www.aliexpress.com/item/2017-New-4-LAN-Core-I5-5250U-Fanless-Micro-PC-home-routerSupport-pfsense-linux-firewall-etc/32798522352.html?spm=2114.search0104.3.1.iaQOEt&ws_ab_test=searchweb0_0,searchweb201602_3_10152_10065_10151_10130_10068_10344_5620015_10345_10547_10342_10546_10343_10340_10341_10548_10545_10541_10307_5640015_10060_10155_10154_10056_10055_10539_10538_5370015_10537_10536_10059_10534_10533_100031_10103_10102_10142_10107_10324_10325_10084_10083_10178_10312_10313_10314_10073_5630015_5720013,searchweb201603_2,ppcSwitch_5&btsid=493ac3ca-1225-49bc-954f-115c031fa3b9&algo_expid=1ae04118-dfee-4ea0-b573-6b4aa4f7e47e-0&algo_pvid=1ae04118-dfee-4ea0-b573-6b4aa4f7e47e

Edit 2: I couldn't find any difference other than price and some of the configuration options are slightly different depending on which page you're looking at. I ended up order the first link I posted above (4Gb RAM/32Gb SSD) based on it having significantly more reviews.