Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
Send IPS alerts by e-mail
« previous
next »
Print
Pages: [
1
]
Author
Topic: Send IPS alerts by e-mail (Read 2750 times)
opleksin
Newbie
Posts: 1
Karma: 0
Send IPS alerts by e-mail
«
on:
July 24, 2020, 06:57:51 pm »
I successfully set up and configured IPS in opnsense. If I try to open a TCP connection from inside my network to a host listed, e.g., in the ET botnet list, the connection is blocked and I get an alert. So far, so good.
The problem is: The alert shows up in the opnsense web UI. I don't want to regularly check the web UI for alerts. If an alert happens, I'd like to be notified (by e-mail), so that I can investigate whether this is a security incident or a false positive.
Is there some built-in functionality in opnsense to activate this kind of e-mail notification? I activated Monit, but none of the built-in service alerts seems to relate to the IPS.
Thanks and best regards
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Send IPS alerts by e-mail
«
Reply #1 on:
July 25, 2020, 07:57:47 am »
https://github.com/opnsense/docs/blob/master/source/manual/monit.rst
Example 3
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Julien
Hero Member
Posts: 666
Karma: 33
Re: Send IPS alerts by e-mail
«
Reply #2 on:
August 19, 2020, 11:28:48 pm »
This is really handy have you managed to configure it ?
Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023
XeroX
Full Member
Posts: 114
Karma: 7
Re: Send IPS alerts by e-mail
«
Reply #3 on:
August 23, 2020, 12:06:44 am »
Yes, but I find this more annoying than helpful.
Logged
chemlud
Hero Member
Posts: 2485
Karma: 112
Re: Send IPS alerts by e-mail
«
Reply #4 on:
August 23, 2020, 11:45:00 am »
...if you are not interested in what's going on in your network simply turn off suricata :-p
Carefully select your rulesets for your use case and turn off false positives ove time. IPS is not a feature you turn on and forget about it...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare
felix eichhorns premium katzenfutter mit der extraportion energie
A router is not a switch - A router is not a switch - A router is not a switch - A rou....
XeroX
Full Member
Posts: 114
Karma: 7
Re: Send IPS alerts by e-mail
«
Reply #5 on:
August 23, 2020, 02:57:35 pm »
I agree if running IDS, but I'm running IPS. I want to block malicous traffic to my exposed systems.
I don't need notifications for any DShield blocks so I check that manually from day to day.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
Send IPS alerts by e-mail