OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of teej1980uk »
  • Show Posts »
  • Topics
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Topics - teej1980uk

Pages: [1]
1
24.1 Legacy Series / Suricata IPS Block Bad Actors - Add to Firewall Alias Group
« on: May 19, 2024, 09:19:17 pm »
Hi.

Long timer listener, first time caller :)

Is it possible to add some automation in to add a bad actor source IP from Suricata /var/log/suricata/eve.json and to add the offending IP into a Firewall alias group?

Perhaps using Monit, Shell Script, Cron, Fail2Ban or some API call?

I think this would be an invaluable feature, and would save me from manually logging to reduce/secure the attack surface.

Many thanks.

Pages: [1]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2