OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • IDS and Firewall Rules
« previous next »
  • Print
Pages: [1]

Author Topic: IDS and Firewall Rules  (Read 2289 times)

cbyrd

  • Newbie
  • *
  • Posts: 9
  • Karma: 1
    • View Profile
IDS and Firewall Rules
« on: October 09, 2017, 07:00:02 pm »
When are IDS rules applied as compared to the firewall rules.

I am doing country blocks in IDS but would like to pass certain email servers in the blocked areas.

I have a firewall rule to allow them but they are still getting blocked by the IDS.

Is there a way away to allow specific IP through in IDS ?

Any help appreciated.
Chris
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13633
  • Karma: 1174
    • View Profile
Re: IDS and Firewall Rules
« Reply #1 on: October 09, 2017, 10:59:02 pm »
Hi Chris,

The IDS blocking is a level below the firewall itself, so the IDS is protecting your whole firewall system, but also blocks more strongly than your firewall and exceptions won't work from there.

But firewall aliases also provide solid geo blocking. You should consider switching to the those as they gives you fine-grained control over the block targets (or add exceptions).


Cheers,
Franco
Logged

cbyrd

  • Newbie
  • *
  • Posts: 9
  • Karma: 1
    • View Profile
Re: IDS and Firewall Rules
« Reply #2 on: October 10, 2017, 04:42:03 am »
Franco,

Thank you for the insight.      Does using Geoblocking in the firewall affect performance vs the IDS.

I was using geoblocking in the firewall rules and I was getting an error that it was unable to load the rule in memory.    I did have lots of countries blocked.

Chris
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13633
  • Karma: 1174
    • View Profile
Re: IDS and Firewall Rules
« Reply #3 on: October 10, 2017, 07:17:07 am »
Hi Chris,

This is not a problem. The search for the error should be trivial in the forum if you provide the exact message, but I'm feeling lucky today:

https://forum.opnsense.org/index.php?topic=4524.msg17330#msg17330

Performance should be the the same except for very large deployments, although remember you aim for more flexibility by accepting a bit less performance so that's a reasonable tradeoff. :)


Cheers,
Franco
« Last Edit: October 10, 2017, 07:19:03 am by franco »
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • IDS and Firewall Rules
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2