1
General Discussion / Port Scanning block and Port Knocking - is it possible in OPNsense
« on: July 13, 2021, 08:42:30 pm »
Hi,
I have 2 questions, but they could be connected maybe to one solution.
I would like to know if there some utility or settings to have some rule to block simple port scanning???
It is like in Mikrotik, where you could have some detection of portscanning by setting weight to scanned ports.
There are some rules which then put remote attackers on list and blocks them before they get to IDS/IPS.
Some solution for this ?
There is another request from my customer to have option to use portknock.
Is some way to use it in OPNsense firewall ? Mainly it works that there is some defined port opening sequence and when it is used from allowed address it opens some port in firewall.
This could be some option to have as feature in OPNsense maybe
Or is it solved by Suricata or SENSEI ?
I have 2 questions, but they could be connected maybe to one solution.
I would like to know if there some utility or settings to have some rule to block simple port scanning???
It is like in Mikrotik, where you could have some detection of portscanning by setting weight to scanned ports.
There are some rules which then put remote attackers on list and blocks them before they get to IDS/IPS.
Some solution for this ?
There is another request from my customer to have option to use portknock.
Is some way to use it in OPNsense firewall ? Mainly it works that there is some defined port opening sequence and when it is used from allowed address it opens some port in firewall.
This could be some option to have as feature in OPNsense maybe
Or is it solved by Suricata or SENSEI ?