OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Documentation and Translation (Moderator: fabian) »
  • [SOLVED] Intrusion detection documentation
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] Intrusion detection documentation  (Read 13079 times)

DoubleJ

  • Newbie
  • *
  • Posts: 20
  • Karma: 2
    • View Profile
[SOLVED] Intrusion detection documentation
« on: October 03, 2015, 02:07:06 pm »
Does anyone know where to find any information, documentation or help files on opnsense's intrusion detection?

thnx in advance
« Last Edit: February 24, 2016, 01:43:04 pm by jschellevis »
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17706
  • Karma: 1618
    • View Profile
Re: Intrusion detection documentation
« Reply #1 on: October 11, 2015, 01:46:55 pm »
Hi there,

the feature is "quite" new and was rebuilt from the ground up, we don't have more documentation than what is scattered around the forum I fear. Are you looking for a specific piece of info or just a general introduction?


Cheers,
Franco
Logged

DoubleJ

  • Newbie
  • *
  • Posts: 20
  • Karma: 2
    • View Profile
Re: Intrusion detection documentation
« Reply #2 on: October 26, 2015, 05:36:11 pm »
I'm interested introduction. What is the functionality of the service? does it block or only registers? What are rulesets? what is the diff with the rules tab? what does every rule or ruleset do (criteria?) ?

I want to understand the service; decide whether it is useful in my situation and if so, what config options are of interest.
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17706
  • Karma: 1618
    • View Profile
Re: Intrusion detection documentation
« Reply #3 on: October 27, 2015, 11:19:58 am »
Jos is working on new material, I'll ask if he has this planned already. Thanks for your feedback. :)
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17706
  • Karma: 1618
    • View Profile
Re: Intrusion detection documentation
« Reply #4 on: October 28, 2015, 10:43:26 pm »
This is what I could gather from a rather busy Jos:

Quote
No I don’t have anything for IDS, but the current IDS is straight forward just enable a ruleset and then you can apply individual rules or keep the defaults. Currently it only generates alerts, visible in the Alert tab.. that is it.. testing it will take 5-10 minutes ;-)

For 16.1 it will become a little bit more difficult as then you should be able to change the behavior from alert to block.
Logged

DoubleJ

  • Newbie
  • *
  • Posts: 20
  • Karma: 2
    • View Profile
Re: Intrusion detection documentation
« Reply #5 on: October 31, 2015, 05:41:07 pm »
Ok thnx, I'll play around with it.
Logged

jschellevis

  • Administrator
  • Full Member
  • *****
  • Posts: 156
  • Karma: 37
    • View Profile
Re: Intrusion detection documentation
« Reply #6 on: February 24, 2016, 01:42:39 pm »
Documentation has been updated for many topics including the IDP and inline IPS solution.

See: https://docs.opnsense.org/manual/ips.html
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Documentation and Translation (Moderator: fabian) »
  • [SOLVED] Intrusion detection documentation
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2