@Patrick M. Hausen
Thank you for the feedback, they are always welcome.
> - Distributed setup is a real pain when the hub is to be OPNsense, because credentials remote machines use to send events get overwritten every so often if you are not ultra careful. OK, operator error, but a bit of POLA violation, too. Reset to localhost and new secret happens much too easily.
I'm sorry about this, but the aspect you're talking about cannot really be adjusted on our end since it's mainly related to OpnSense. You could run a distributed WAF/IDS setup directly on the machines themselves, which is more the way larger system usually leverage CrowdSec.
> - The blocklists available for free tier users are not well maintained and essentially worthless. Specifically while free tier users contribute to the main CrowdSec blocklist we do not get to subscribe to it for free.
Well sorry about the feeling around the Free Tier BL. it's updated several time a day and shares back depending on what you share too. So if you setup isn't sending back signals or just on a specific scenario like bruteforce, you'd get back some bruteforce BL. We contribute to free tier users by offering the scenario, engine, rules, the free tier and free BL so I think there is quite some reciprocal sharing. If we give all the BLs for free too, we simply have no business model anymore and cannot maintain the FOSS part of the system.
> - There is no affordable (like 100 $/€/£ per year) subscription offer for home users which I would seriously consider.
It depends highly on what you're looking to improve, if it's alert retention, there is actually a package to just boost this. If it's a BL, no I don't think we have anything in this range, but a lot in the range of 360€ yearly. I know it's a gap, but for a B2B offer, this is the lowest price point we could come up with so far. We tried lower price points but had no specific adoption boost covering the gap.
> So I stopped using it entirely. I currently have a running subscription for Q-Feeds and I am quite satisfied with the results.
CrowdSec is first and foremost a WAF and IDS, sharing threats between your machines and within the global network.
Indeed if the goal was to have rather Feeds for $100/y, the offer from qfeeds may be more adapted to your context.
to @cookiemonster:
> At the moment, the CrowdSec package for OPNsense is fully functional on the command line but its web interface is limited; you can only list the installed objects and revoke decisions. For anything else you need the shell or the CrowdSec Console. Which means most of the existing and new functionality is unmanageable from the plugin. For instance I can't use SPOA for haproxy on OPN when using the OPN haproxy plugin. If you are still willing to listen to my points (thank you for the offer) I shall open a new post so we can discuss them. In the open I suspect will be suitable for other users too. If you agree. Again, thank you. Just confirm and I will.
Sure, I think the product team would be delighted to exchange. Feel free to contact us (my 1st name @crowdsec.net) and open the exchange. I don't know what relies on OpnSense's team shoulder and what's on our own regarding this specific point tbh, neither what's doable or not but we can discuss it. Also, again, if you want to run a larger, more complex setup, I'd encourage you to use an autonomous instsance of CrowdSec. Also of note, you can use our CrowdSec Skill for Claude if you want.
Thank you for the feedback, they are always welcome.
> - Distributed setup is a real pain when the hub is to be OPNsense, because credentials remote machines use to send events get overwritten every so often if you are not ultra careful. OK, operator error, but a bit of POLA violation, too. Reset to localhost and new secret happens much too easily.
I'm sorry about this, but the aspect you're talking about cannot really be adjusted on our end since it's mainly related to OpnSense. You could run a distributed WAF/IDS setup directly on the machines themselves, which is more the way larger system usually leverage CrowdSec.
> - The blocklists available for free tier users are not well maintained and essentially worthless. Specifically while free tier users contribute to the main CrowdSec blocklist we do not get to subscribe to it for free.
Well sorry about the feeling around the Free Tier BL. it's updated several time a day and shares back depending on what you share too. So if you setup isn't sending back signals or just on a specific scenario like bruteforce, you'd get back some bruteforce BL. We contribute to free tier users by offering the scenario, engine, rules, the free tier and free BL so I think there is quite some reciprocal sharing. If we give all the BLs for free too, we simply have no business model anymore and cannot maintain the FOSS part of the system.
> - There is no affordable (like 100 $/€/£ per year) subscription offer for home users which I would seriously consider.
It depends highly on what you're looking to improve, if it's alert retention, there is actually a package to just boost this. If it's a BL, no I don't think we have anything in this range, but a lot in the range of 360€ yearly. I know it's a gap, but for a B2B offer, this is the lowest price point we could come up with so far. We tried lower price points but had no specific adoption boost covering the gap.
> So I stopped using it entirely. I currently have a running subscription for Q-Feeds and I am quite satisfied with the results.
CrowdSec is first and foremost a WAF and IDS, sharing threats between your machines and within the global network.
Indeed if the goal was to have rather Feeds for $100/y, the offer from qfeeds may be more adapted to your context.
to @cookiemonster:
> At the moment, the CrowdSec package for OPNsense is fully functional on the command line but its web interface is limited; you can only list the installed objects and revoke decisions. For anything else you need the shell or the CrowdSec Console. Which means most of the existing and new functionality is unmanageable from the plugin. For instance I can't use SPOA for haproxy on OPN when using the OPN haproxy plugin. If you are still willing to listen to my points (thank you for the offer) I shall open a new post so we can discuss them. In the open I suspect will be suitable for other users too. If you agree. Again, thank you. Just confirm and I will.
Sure, I think the product team would be delighted to exchange. Feel free to contact us (my 1st name @crowdsec.net) and open the exchange. I don't know what relies on OpnSense's team shoulder and what's on our own regarding this specific point tbh, neither what's doable or not but we can discuss it. Also, again, if you want to run a larger, more complex setup, I'd encourage you to use an autonomous instsance of CrowdSec. Also of note, you can use our CrowdSec Skill for Claude if you want.
"