1
Zenarmor (Sensei) / Re: Sensei on OPNsense - Application based filtering
« on: August 23, 2019, 03:22:16 pm »
Hello,
Been an OpenSense User for a few months now, switched from pFsense. Love it so far.
Maybe like others here, I'm a cryptocurrency enthusiast and I need to strengthen the security of my machine where my wallets run on. I'm planning on moving it to a separate VLAN and authorize only specific ports for the wallets that need them. I want no web trafic on it. However while checking the traffic to list the ports I need to let through, I see two of the wallets I have (which are multiasset) use 443 and I want to avoid just opening 443 on that VLAN.
Where I work we use a PaloAlto firewall and the application based filtering is really handy. I just discovered Sensei and I'm playing around with it. I assume you could let 443 through for a specific application.
One question: is there a way to add custom application to the app control that aren't in the list?
I think this answers it: https://help.sunnyvalley.io/hc/en-us/articles/360025098033
But still wanted a confirmation.
Thanks!
Been an OpenSense User for a few months now, switched from pFsense. Love it so far.
Maybe like others here, I'm a cryptocurrency enthusiast and I need to strengthen the security of my machine where my wallets run on. I'm planning on moving it to a separate VLAN and authorize only specific ports for the wallets that need them. I want no web trafic on it. However while checking the traffic to list the ports I need to let through, I see two of the wallets I have (which are multiasset) use 443 and I want to avoid just opening 443 on that VLAN.
Where I work we use a PaloAlto firewall and the application based filtering is really handy. I just discovered Sensei and I'm playing around with it. I assume you could let 443 through for a specific application.
One question: is there a way to add custom application to the app control that aren't in the list?
I think this answers it: https://help.sunnyvalley.io/hc/en-us/articles/360025098033
But still wanted a confirmation.
Thanks!