Home networks in IDS/IPS

Started by hushcoden, September 20, 2020, 01:53:27 PM

Previous topic - Next topic
September 20, 2020, 01:53:27 PM Last Edit: September 20, 2020, 02:22:26 PM by hushcoden
If I'm running the IDS on the WAN interface only, in the 'Home networks' section should I enter:

1) WAN address only

2) LAN networks only

3) WAN address + LAN networks

Tia.

Run it on the LAN address and in the "Home Networks" add the WAN address.
Regards


Bill

Quote from: phoenix on September 20, 2020, 03:23:00 PM
Run it on the LAN address and in the "Home Networks" add the WAN address.
I can't run it on LAN as I'm using Sensei on LAN...

Anyone can give a definite answer, please ?

Thanks.


If Sensei runs on LAN.
then WAN only for IDS/IPS.


English: Never try, never know!
Deutsch: Unversucht ist Unerfahren!

Quote from: ArminF on September 26, 2020, 06:55:19 PM
If Sensei runs on LAN.
then WAN only for IDS/IPS.
So, are you saying that Suricata doens't need to know your LAN IP addresses if it runs on WAN only ?

Referring to the picture attached and link https://docs.opnsense.org/manual/ips.html

Interface Selection
Suricata will listen on the interfaces you select. WAN and or DMZ.

Home networks
Define custom home networks, when different than an RFC1918 network. In some cases, people tend to enable IDPS on a wan interface behind NAT (Network Address Translation), in which case Suricata would only see translated addresses in stead of internal ones. Using this option, you can define which addresses Suricata should consider local.

Here actually you do not need to enter except you are outside of any 192.168 / 172.16 or 10.x.x.x network. I usually tend to enter it. Just to make sure Suricata can map the traffic from home to wan. As most of the home setups are in NAT Mode i would enter the local networks.

Hope this explains better.
English: Never try, never know!
Deutsch: Unversucht ist Unerfahren!