Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Do I Need IPS ?

    Scheduled Pinned Locked Moved Firewalling
    22 Posts 10 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DaddyGoD
      DaddyGo @bmeeks
      last edited by

      @bmeeks said in Do I Need IPS ?:

      Agree wholeheartedly with @johnpoz here. On a home network, an IPS requires a lot of upfront knowledge to configure and a lot of labor to maintain.

      Hi Bill,
      Long time no "see", but I hope all is well.

      Very true, but I still love this approach (if I can call it IPS stuff), sure the yes the learning curve can be steep, but let's not take away anyone's enthusiasm.
      When you're pushing this in a production environment, you're past a home and/or VM/test system... ๐Ÿ˜‰ (I hope so)

      BTW:
      I'm still impressed by your work ๐Ÿ‘

      Cats bury it so they can't see it!
      (You know what I mean if you have a cat)

      bmeeksB 1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks @DaddyGo
        last edited by bmeeks

        @DaddyGo said in Do I Need IPS ?:

        sure the yes the learning curve can be steep, but let's not take away anyone's enthusiasm.

        I don't mean to discourage someone who wants to try it out for the learning experience, but there are a fair number of users that install it without fully understanding what it is and how to maintain it. They then post here with frustrations because something is blocked. Unintended blocking will happen a lot with a typical home setup unless the admin is skilled in the craft of IDS/IPS.

        But this is also a problem with all of the packages that can "block things" such as Snort, Suricata, pfBlocker, SquidGuard, etc. I am always amazed at the posts where someone installs one or more of those packages on their pfSense and then posts asking "... why is pfSense blocking xyz site?". It makes me want to whack them on the side of their head and ask "do you think it could possibly be one of those packages you installed that are intrinsically designed to block stuff? Have you checked if one of those packages is blocking the desired traffic?" ๐Ÿ™‚ . And many times it takes two or three rounds of back and forth questions to pry out of them the tidbit that they have indeed installed one (or even several) of the blocking packages.

        M DaddyGoD 2 Replies Last reply Reply Quote 3
        • M
          michmoor LAYER 8 Rebel Alliance @bmeeks
          last edited by

          @bmeeks The pros and cons of making a product available to the masses.
          The solution would be to gatekeep this behind a VAR and high cost support packages :)

          Firewall: NetGate,Palo Alto-VM,Juniper SRX
          Routing: Juniper, Arista, Cisco
          Switching: Juniper, Arista, Cisco
          Wireless: Unifi, Aruba IAP
          JNCIP,CCNP Enterprise

          O DaddyGoD 2 Replies Last reply Reply Quote 0
          • O
            oznet @michmoor
            last edited by

            @michmoor sounds like I will fore go the IPS aspect and stick to blocking ads

            1 Reply Last reply Reply Quote 0
            • JonathanLeeJ
              JonathanLee
              last edited by JonathanLee

              DO IT!!! IPS/IDS both have fun setting it up too,

              I added some alias rules to do not block lists as SNORT takes some time to fine tune, once it's tuned its great!!

              d9663fab-1bf1-449d-b4db-a13f60f0c157-image.png
              83 plus blocks in 1 hour of invasive actors.

              1330a158-0b82-4ef5-a4f2-b8ac1d10b17a-image.png
              Mine even does auto scan blocking, that was fun to set up as roblox like to scan when it starts up.

              1c96cbf5-4562-4d67-bc37-260fe0e6f61f-image.png
              I have a nice ACL for it, plus a ignore scans set

              9068dce5-ac4c-4d2f-a57c-e4b478640082-image.png
              I ignore a pretty big block of addresses that Roblox uses or Snort blocks them all when it sees a UDP scan

              It's the 1990s Air-Snort application upgraded, anyone play with that in the 90s, I use to see 0.0.0.0 MACs sometimes back in the day.

              Make sure to upvote

              C 1 Reply Last reply Reply Quote 0
              • DaddyGoD
                DaddyGo @bmeeks
                last edited by

                @bmeeks said in Do I Need IPS ?:

                but there are a fair number of users that install it without fully understanding what it is and how to maintain it.

                yes, this can be seen in many scenarios and when they fall flat on their face they realise what they have done wrong ๐Ÿ˜Š

                +++edit:
                at least they will have something to ask here on the forum

                Cats bury it so they can't see it!
                (You know what I mean if you have a cat)

                1 Reply Last reply Reply Quote 0
                • DaddyGoD
                  DaddyGo @michmoor
                  last edited by

                  @michmoor said in Do I Need IPS ?:

                  The solution would be to gatekeep this behind a VAR and high cost support packages :)

                  that would be quite terrible ๐Ÿ˜Š

                  Cats bury it so they can't see it!
                  (You know what I mean if you have a cat)

                  1 Reply Last reply Reply Quote 0
                  • C
                    coxhaus @JonathanLee
                    last edited by

                    @JonathanLee
                    Are you running it on the WAN or the LAN side?

                    I plan to run it. I am waiting for 23.09 first.

                    Do any of Pfsense's IPS/IDS use Intel's Hyperscan? Maybe that is the real SNORT 3?

                    https://www.intel.com/content/www/us/en/developer/articles/technical/introduction-to-hyperscan.html

                    JonathanLeeJ 1 Reply Last reply Reply Quote 0
                    • JonathanLeeJ
                      JonathanLee @coxhaus
                      last edited by

                      @coxhaus WAN it does take a while to configure this way. Most use Lan today

                      Make sure to upvote

                      C 1 Reply Last reply Reply Quote 0
                      • C
                        coxhaus @JonathanLee
                        last edited by

                        @JonathanLee
                        I used WAN years ago. Never used LAN.

                        DaddyGoD 1 Reply Last reply Reply Quote 1
                        • DaddyGoD
                          DaddyGo @coxhaus
                          last edited by

                          @coxhaus said in Do I Need IPS ?:

                          I used WAN years ago. Never used LAN.

                          I do have some problems with this though, pfS "drop" everything on the WAN by default and it's a noisy interface and look at this one Bill knows it best:

                          https://forum.netgate.com/topic/76141/snort-on-lan-wan/5?_=1695283899257

                          Cats bury it so they can't see it!
                          (You know what I mean if you have a cat)

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.