OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • How do you configure Intrusion Detection in OPNsense?
« previous next »
  • Print
Pages: [1]

Author Topic: How do you configure Intrusion Detection in OPNsense?  (Read 15496 times)

comet

  • Full Member
  • ***
  • Posts: 117
  • Karma: 4
    • View Profile
How do you configure Intrusion Detection in OPNsense?
« on: November 15, 2017, 09:21:05 pm »
One of the things I would like to try in OPNsense is enabling Intrusion Detection but I know absolutely nothing about it.  Is their some kind of easy guide to setting up Intrusion Detection in OPNsense?  I'm assuming that you need to do something more than just checking the box for "Enabled", but most of the other options are meaningless to me.

What I'd like, if possible, is to stop intrusions but without blocking traffic to sites I use.  And I actually know so little about Intrusion Detection that I am currently not clear whether it operates only on inbound packets, outbound packets, or both.

Intrusion Detection is not a feature that I've had on any previous router.  When I briefly looked at other software, I noticed they let you add "Snort" which (I think) was also a form of intrusion detection, but it seemed a bit easier to set up since you could pick from three different pre-configured levels of protection (not saying that's the right way to do it, just that it might have been easier to set up). I don't see anything like that in the OPNsense Intrusion Detection feature, and I'm totally lost!  I hope it is not too difficult to at least enable some basic level of Intrusion Detection.

Please feel free to point me to any good beginner-level pages or videos on the subject, if any exist.  Thanks!
Logged
I'm a home user of OPNsense, not a networking expert.  I'd much appreciate it if you'd keep that in mind if replying to something I posted.  Many thanks!

phoenix

  • Hero Member
  • *****
  • Posts: 545
  • Karma: 58
    • View Profile
Re: How do you configure Intrusion Detection in OPNsense?
« Reply #1 on: November 15, 2017, 09:37:55 pm »
Have you had a look at the OPNsense Documentation on IDS/IPS: https://wiki.opnsense.org/manual/ips.html?highlight=suricata
Logged
Regards


Bill

comet

  • Full Member
  • ***
  • Posts: 117
  • Karma: 4
    • View Profile
Re: How do you configure Intrusion Detection in OPNsense?
« Reply #2 on: November 15, 2017, 10:07:51 pm »
Quote from: phoenix on November 15, 2017, 09:37:55 pm
Have you had a look at the OPNsense Documentation on IDS/IPS: https://wiki.opnsense.org/manual/ips.html?highlight=suricata
Yeah, I saw that, and no offense intended, but I found it worse than useless.  It did not give me ANY useful information on how to set up and configure Intrusion Detection.  When you go to documentation, you sort of expect it will give you information on how to set up that feature, and that page doesn't.  At all.
Logged
I'm a home user of OPNsense, not a networking expert.  I'd much appreciate it if you'd keep that in mind if replying to something I posted.  Many thanks!

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: How do you configure Intrusion Detection in OPNsense?
« Reply #3 on: November 16, 2017, 01:30:54 am »
It’s a manual overview page, not a how to. The first how to on that page explains how to use IDS with SSL rules.


Cheers,
Franco
Logged

xames

  • Full Member
  • ***
  • Posts: 110
  • Karma: 3
    • View Profile
Re: How do you configure Intrusion Detection in OPNsense?
« Reply #4 on: January 01, 2019, 07:54:28 pm »
agree with comet, no good manual out there.
Logged

xames

  • Full Member
  • ***
  • Posts: 110
  • Karma: 3
    • View Profile
Re: How do you configure Intrusion Detection in OPNsense?
« Reply #5 on: January 17, 2019, 08:47:48 pm »
Manual is always refering to IPS not to IDS, what is exactly the differents between them?
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: How do you configure Intrusion Detection in OPNsense?
« Reply #6 on: January 18, 2019, 09:33:47 am »
I'm afraid that's not something we should cover in our manual in any greater detail and I think it has surely been answered in this forum before.


Cheers,
Franco
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • How do you configure Intrusion Detection in OPNsense?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2