OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Windows Updates
« previous next »
  • Print
Pages: 1 [2]

Author Topic: Windows Updates  (Read 16435 times)

elektroinside

  • Hero Member
  • *****
  • Posts: 574
  • Karma: 51
    • View Profile
Re: Windows Updates
« Reply #15 on: January 20, 2018, 11:00:05 am »
As it turns out, not all dropped packets are logged.
I have modified suricata.yaml to log all of them.

Setting these sids to 'Alert' fixed my Windows Updates issues:

2023818
2020573

@Franco: may i suggest to revise this part of the suricata config? It will avoid a lot of confusions...
Logged
OPNsense v18 | HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s

Team Rebellion Member

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: Windows Updates
« Reply #16 on: January 20, 2018, 08:45:31 pm »
Hey elektroinside ,

Thanks for the heads-up! This one should do it? :)

https://github.com/opnsense/core/commit/573612d48


Cheers,
Franco
Logged

elektroinside

  • Hero Member
  • *****
  • Posts: 574
  • Karma: 51
    • View Profile
Re: Windows Updates
« Reply #17 on: January 20, 2018, 09:29:46 pm »
I don't know.. yet :)
Hopefully, it's enough, I'll let you know in a few days, probably enough time to generate lots of packets :)

I am seeing some dropped packets right now, don't remember seeing them before, so it might work :)

Thank you Franco!

Logged
OPNsense v18 | HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s

Team Rebellion Member

dcol

  • Hero Member
  • *****
  • Posts: 635
  • Karma: 51
    • View Profile
Re: Windows Updates
« Reply #18 on: January 21, 2018, 09:34:59 pm »
I also implemented this change
Can't tell if the change does anything since I also saw blocks before the change.
I take it that eve.json is the IDS alerts list.

elektroinside - I figured the updates problems were rules. Glad you found it. I didn't see it because I do not have those rulesets enabled.
Logged

elektroinside

  • Hero Member
  • *****
  • Posts: 574
  • Karma: 51
    • View Profile
Re: Windows Updates
« Reply #19 on: January 22, 2018, 07:45:08 am »
Figured it had something to do with alerting (the fact that i can't see what is blocked and what is not, from previous experiences with suricata). Also, without this change in the config file, you couldn't see it anyway, even if you had the rule, as it was not logged (dropped silently).

Anyway, it's all good now :-) Thank you both!
Logged
OPNsense v18 | HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s

Team Rebellion Member

Ciprian

  • Sr. Member
  • ****
  • Posts: 284
  • Karma: 50
    • View Profile
Re: Windows Updates
« Reply #20 on: January 22, 2018, 08:54:28 am »
Quote from: franco on January 20, 2018, 08:45:31 pm
Hey elektroinside ,

Thanks for the heads-up! This one should do it? :)

https://github.com/opnsense/core/commit/573612d48


Cheers,
Franco

And maybe (rather, surely) from now on it is a lot more easy to find the culprit rule(s) or ruleset(s) crippling any other network service.
Logged

  • Print
Pages: 1 [2]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Windows Updates
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2