Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
If in IPS mode some of your sites may soon get blocked
« previous
next »
Print
Pages: [
1
]
Author
Topic: If in IPS mode some of your sites may soon get blocked (Read 46 times)
someone
Full Member
Posts: 102
Karma: 2
If in IPS mode some of your sites may soon get blocked
«
on:
Today
at 12:46:04 am »
Opnsense rulesets have started working
ET rulesets have not
They are working on it
When ET rulesets start working some of your favorite sites may be blocked
Many sites are blocked by rules, for instance
sid 2013504 will stop you from doing Ubuntu updates
sid 2100366 will stop you from doing any ping
There are social media blocking rules
If you use Kali linux you will get blocked
So
Before this happens in an upcoming update,
I just checked they are not working yet
Go to services > intrusion detection > administration > rules
In the search box type in facebook and you will see the rules
If thats a site you use you can disable them now, before the update
Find blocked sites by typing in their name or IP
Can also type their IP in alerts search box if they get blocked to find the rule blocking them
Can find an IP by googling it or on command line using $host google.com
it will give you some of googles IPs
they have many, just an example
They fixed opnsense rules very fast
Thing with ET rules is they are downloaded in a strict format to work with different parties and not just opnsense
I dont think opnsense wants to change them every update
So it may take some modification of suricata, or a program in opnsense to make them work
They are working on it
So I am letting you know before you get some sites blocked after a update
Which update I dont know
But now you are aware and know your system did not break, just check your rules
Logged
someone
Full Member
Posts: 102
Karma: 2
Re: If in IPS mode some of your sites may soon get blocked
«
Reply #1 on:
Today
at 01:59:41 am »
Just a note
But if you dont want every social media site to know when you come online
And your using firefox
go to settings > home
and uncheck shortcuts
They are beacons
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
If in IPS mode some of your sites may soon get blocked