QuoteI think that the options were set by default to follow the Suricata 6 behavior.
That's what I thought as well when I read the upgrade announcement, but, apparently, the app-layer.error-policy value still follows Suricata 7 behavior: Our VNC repeater connections work in IPS mode only if I manually set
Code Select
app-layer:
error-policy: ignore
in /usr/local/opnsense/service/templates/OPNsense/IDS/custom.yaml.
The planned checkbox would allow me to get rid of that customization.
I have to admit that I'm not a suricata expert. If there is a better way to "whitelist" a custom app-layer protocol to a specific port on a specific IP, I'm open to suggestions.