If I look at the security policies, I can enable the block for sites that are responsible for malware, phishing, etc - am I right to say that what Sensei does here is to block access to/from a list of malicious IPs, that is the same I can configure with the blocklist feature in Unbound ?Or adding rules as for this article https://docs.opnsense.org/manual/how-tos/edrop.html
Yes, I'm aware of the features of the different versions...Can you answer my question ?QuoteIf I look at the security policies, I can enable the block for sites that are responsible for malware, phishing, etc - am I right to say that what Sensei does here is to block access to/from a list of malicious IPs, that is the same I can configure with the blocklist feature in Unbound ?Or adding rules as for this article https://docs.opnsense.org/manual/how-tos/edrop.html
Unbound block list only works for DNS calls. Sensei does not care about DNS (you may even use DoT or DoH), but it actually inspects the connections to see where they go.
Quote from: almodovaris on August 28, 2021, 02:42:19 pmUnbound block list only works for DNS calls. Sensei does not care about DNS (you may even use DoT or DoH), but it actually inspects the connections to see where they go.So, if it's checking the potential malicious IP addresses, this is can be done by creating alias(es) and rules as per that article I've mentioned https://docs.opnsense.org/manual/how-tos/edrop.html ?