OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Zenarmor (Sensei) »
  • This is basic, just can't find it
« previous next »
  • Print
Pages: [1]

Author Topic: This is basic, just can't find it  (Read 1257 times)

starfox101

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
This is basic, just can't find it
« on: December 05, 2023, 05:14:44 pm »
detected 14 and blocked 11 potentially harmful activities according to your rules. How do I find the detected harmful activities? Figure out if I should block them.

Thanks
Logged

almodovaris

  • Sr. Member
  • ****
  • Posts: 318
  • Karma: 15
    • View Profile
Re: This is basic, just can't find it
« Reply #1 on: December 05, 2023, 05:19:30 pm »
https://dash.zenarmor.com/firewalls/

Under Live sessions. Then apply what filters you want in order to see what was there.

Generally speaking, it only blocks what you choose to block. If there are other blockable connections, but you did not choose to block them, they will appear as "harmful".

E.g. I don't block proxies, so proxies will appear as "harmful", but they do not get blocked.
Logged
OPNsense HW:

Minisforum Venus series UN100C, 16 GB RAM, 512 GB SSD
T-bao N9N Pro, 16 GB RAM, 512 GB SSD

starfox101

  • Newbie
  • *
  • Posts: 32
  • Karma: 0
    • View Profile
Re: This is basic, just can't find it
« Reply #2 on: December 05, 2023, 06:20:38 pm »
Thanks for the reply, I guess I'll have to figure out the filters.
Logged

beki

  • Jr. Member
  • **
  • Posts: 94
  • Karma: 10
    • View Profile
Re: This is basic, just can't find it
« Reply #3 on: December 06, 2023, 08:11:28 am »
Hi starfox101,
With the forthcoming release 1.16, the firewall dashboard will provide direct access to Live Sessions for "Blocked Threats" and "Detected Threats," expediting traffic analysis and threat detection.

A display will appear when you select the quantity of blocked threats, which is Threats Live Sessions filtering blocked connections. You can then simply exclude the Blocked filter in order to view detected threats that have not been blocked by selecting the equals (=) symbol on the applied filter parameter.

For more information:
https://www.zenarmor.com/docs/opnsense/reporting-analytics/live-session-explorer#adding-a-generic-filterexclusion-on-the-live-session-explorer

Bests
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Zenarmor (Sensei) »
  • This is basic, just can't find it
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2