Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - andrewoliv

#16
Zenarmor (Sensei) / Re: 22.1.8 MongoDB problem
May 27, 2022, 09:45:03 PM
Thanks for the heads up!

I tried to "fix" this by installing and reinstalling sensei and have really messed up my Sensei Plugins.

See attachment

This is what happens when I try to re-install the sensei repository. I have to uninstall the repository and my plugins return to normal.
#17
Zenarmor (Sensei) / Sensei PlugIns Disappear?
May 27, 2022, 09:42:39 PM
See Attachment


Whenever is install the Sensei repository PlugIn it orphans all of my other PlugIns. The sensei plug in never appears. I have to delete the Sensei PlugIn and then the other plugins return to normal.

Anyone else have this problem?
#18
See Attachment.

Whenever is install the Sensei repository PlugIn it orphans all of my other PlugIns. The sensei plug in never appears. I have to delete the Sensei PlugIn and then the other plugins return to normal.

Anyone else have this problem?
#19
I installed the Crowdsec plugin manually on my opnsense firewall. I tested it and it works! However, I installed ver 1.3.2 and upgraded to 1.3.4.  Now the Plug In shows "Misconfigured" on the PlugIn page. I tested again and it seems to still be working. Dont understand the "MisConfigured" message
#20
Thank you for this suggestion.

I have become very frustrated with defining Suricata policies.  I finally got the rules loaded but still get an error message that says the rules are not installed properly.(No indication as to which ones.....)

Suricata seems to detect lots of DNS queries it doesn't understand, not sure how malicious those queries are, I dont like the DNS queries are destined for some obscure DNS server other than DNS server I have defined running DNSSEC and TLS.

In addition the policies I define in Suricata have zero effect on the actual rule.  Lots of "Alert" but no "Drop" like the policy states.

Anyway anything I can do in the FW vs Suricata is very welcome.

I'm sure the issue I am having with Suricata is me and not the software but I cannot seem to find a guide that addresses any of these issues.
#21
I keep getting this alert in my IDS:

Dest IP.             Port  Rule Message     
156.154.67.196   53   ET INFO Observed DNS Query to .biz TLD

I have rules in my firewall preventing external DNS queries yet this keeps getting through.  The rules are applied on all 3 LAN Ports and not on the WAN port.

I checked the IP address its a DNS server with no indications of having a bad reputation.  Is it possible the OPNSense firewall is sending random DNS Requests? I have no other explanation for this. I have watched the live firewall logs and may rules appear to be working.

Any information on this would be helpful

#22
I am trying to learn how to use the Policy feature in Suricata on OpnSense.  Any guides anywhere?
#23
I am running the current version of OPNSense: 22.1.6

I am running Suricata 6.0.4_1

I went to the Snort website and obtained an OINK Code

I go to: Intrusion Detection ==>Administration==>Downloads

I enter the OINK code and Rules file (snortrules-snapshot-29151.tar.gz, 29190 is the latest and I have tried that too)

The Plug In is installed: os-intrusion-detection-content-snort-vrt (installed)

I attempt to download the rules, however I get the message "Not Installed" under the Last Updated heading

What am I missing?