OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Hitting 'Apply' on IDS Policy never(?) completes
« previous next »
  • Print
Pages: [1]

Author Topic: Hitting 'Apply' on IDS Policy never(?) completes  (Read 1132 times)

gctwnl

  • Jr. Member
  • **
  • Posts: 60
  • Karma: 0
    • View Profile
Hitting 'Apply' on IDS Policy never(?) completes
« on: April 21, 2023, 06:27:23 pm »
To make sure the rules I have selected actually drop the traffic, I need to create a Policy that actually changes the default 'alert' on those rules to 'drop'.

So, I created such a rule, but when I clicked 'Apply' for the first time, it was not done after 30 minutes.

CPU usage is low, so what is it doing? Memory usage is high.

This one (a big one on almost all my rulesets) never finished:
Code: [Select]
# cat/usr/local/etc/suricata/rule-policies.config
[843a267bc7314362b09a08d4a25a9f51]
enabled=1
prio=0
rulesets=abuse.ch.feodotracker.rules,abuse.ch.sslblacklist.rules,abuse.ch.sslipblacklist.rules,abuse.ch.threatfox.rules,abuse.ch.urlhaus.rules,botcc.rules,ciarmy.rules,compromised.rules,drop.rules,dshield.rules,emerging-malware.rules,emerging-mobile_malware.rules,emerging-phishing.rules,emerging-web_client.rules,emerging-web_server.rules,opnsense.test.rules
content=
action=drop
__target_action__=drop
__policy_id__=843a267b-c731-4362-b09a-08d4a25a9f51
__policy_description__=Drop everything on these sets
What should I do to get my rulesets to actually block instead of just alert?
Logged

gctwnl

  • Jr. Member
  • **
  • Posts: 60
  • Karma: 0
    • View Profile
Re: Hitting 'Apply' on IDS Policy never(?) completes
« Reply #1 on: April 22, 2023, 12:54:02 pm »
This happened when I load abuse.ch ThreatFox. It does not happen with my current set which excludes ThreatFox
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Hitting 'Apply' on IDS Policy never(?) completes
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2