OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Development and Code Review (Moderator: fabian) »
  • Sensei by-pass rule
« previous next »
  • Print
Pages: [1]

Author Topic: Sensei by-pass rule  (Read 4737 times)

cgwork

  • Newbie
  • *
  • Posts: 19
  • Karma: 1
    • View Profile
Sensei by-pass rule
« on: January 07, 2019, 08:33:26 pm »
Is there an a way i can add a rule for one static IP to bypass sensei filtering?
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei by-pass rule
« Reply #1 on: January 08, 2019, 06:17:00 am »
Hi @cgwork,

For any destination hostname, you can write a whitelist via Web Controls -> User Defined Categories. Just add a new category and put the whitelisted domains into that. Make sure the green tick is there to have them whitelisted.

If you want to do the same for a specific source IP address, this is not possible with current functionality.

Upcoming premium edition will have Policy based filtering, which will enable you to create specific policies based on flow direction (incoming, outgoing, both), local IP addresses, local subnets, VLAN ids, Active Directory Groups or Users. You'll be able to customize Security, App Controls, Web Controls and TLS Inspection per policy. 
« Last Edit: January 08, 2019, 06:31:45 am by mb »
Logged

cgwork

  • Newbie
  • *
  • Posts: 19
  • Karma: 1
    • View Profile
Re: Sensei by-pass rule
« Reply #2 on: January 09, 2019, 03:20:46 pm »
Good Morning, mb

I actually wanted to exclude a internal system to by-pass all the filtering for testing purpose. Do i do this also create an white list for it?

Perfect example is i tried to visit your site https://www.sunnyvalley.io and see a white page on both Firefox and Chrome. I even created a  Web Controls >  User Defined Categories > Testing > your website. Saved the changes but no joy.
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: Sensei by-pass rule
« Reply #3 on: January 10, 2019, 06:46:26 am »
Hi @cgwork,

Understood now, thanks for the additional information.  In terms of source IP based whitelisting, we've designed it as part of policy based filtering, which will be part of the Premium subscription. 
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Development and Code Review (Moderator: fabian) »
  • Sensei by-pass rule
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2