Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
IDS block time
« previous
next »
Print
Pages:
1
[
2
]
Author
Topic: IDS block time (Read 15542 times)
franco
Administrator
Hero Member
Posts: 17656
Karma: 1610
Re: IDS block time
«
Reply #15 on:
November 20, 2017, 10:49:29 pm »
PS: IDS more or less came from tap-based network scenarios, so there was no way to respond either way as hardware was not capable of doing inline analysis yet and that is how the industry treats the IDS / IPS split until today although hardware and software has caught up.
Logged
xinnan
Full Member
Posts: 125
Karma: 13
Re: IDS block time
«
Reply #16 on:
November 20, 2017, 10:53:14 pm »
That wasn't a snipe. Perhaps I need to work on my diplomacy.
Logged
franco
Administrator
Hero Member
Posts: 17656
Karma: 1610
Re: IDS block time
«
Reply #17 on:
November 20, 2017, 10:54:52 pm »
No, I'm not trying to defend anything here, I'm just trying to say what we have and why we have it aside from the fact that other projects may differ in philosophy and implementational details.
Cheers,
Franco
Logged
dcol
Hero Member
Posts: 635
Karma: 51
Re: IDS block time
«
Reply #18 on:
November 21, 2017, 12:08:09 am »
Since inline captures before firewall inspection, there is no need to keep offending IP's. That was a necessity with Snort which used tables to keep a history of offending IP's for the firewall to handle on repeat offenders. But the biggest downside of Legacy is the first packets do make it inside the network before the firewall has a chance to drop it. Really not a 'true' firewall. Like blocking the fire but letting the sparks in.
So building a system around Suricata inline and abandoning Snort IDS makes for the most hardened firewall you can have. This is what hooked me with OPNsense which I consider the best open source firewall available. Now as a user I need to just concentrate on the IDS rules to get the maximum protection. This is where OPNsense needs to concentrate its resources. Rules management.
Logged
Print
Pages:
1
[
2
]
« previous
next »
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
IDS block time