Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - Helle

#1
My upgrade of my system ended with:

The cleanup will free 21 MiB
Deleting files: .......... done
All done
ld-elf.so.1: Shared object "libssl.so.50" not found, required by "opnsense-verify"
Starting web GUI...done.
Generating RRD graphs...done.
ld-elf.so.1: Shared object "libssl.so.50" not found, required by "opnsense-verify"
***DONE***


It never rebooted as it was supposed to do and I am hesitant to reboot until I can expect it to reboot ok.

The gui says it's running 21.7.5 but the installed packages are still .4 and health audit is complaining about not running the expected kernel (which is expected)

The firewall is an APU device with only serial console access so I really want to get some backing before rebooting.

The full installation log is attached
#2
Since some time ago my opnsense box is always giving two lines with identical info when someone is triggered by the IDS/IPS

I run IDS/IPS only on my lan interface and have 11 rule sets enabled..

Any hint is appreciated

/Helle
#3
First post :-)

Is there a way to make abusers detected by suricata to be added to a dynamic firewall-rule for lets say 6hours or a specified time ?

If I get hammering from the outside against a webserver, I would like my opnsense to block the abuser totally and not only some of the php/apache/chmod/suspicios url stuff that suricata detects.

I would feel a lot safer if the detected abuser would be completely blocked for a certain time.
I have not used the other well known pf-based firewall but I believe this is easily done with that platform.

There was someone making a workaround using a webserver to host the list and have the rule pick up hosts but that seems sub optimal IMHO

Any suggestions ?

/Helle