Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Single User -OpenAPPI Rules

    Scheduled Pinned Locked Moved IDS/IPS
    2 Posts 2 Posters 493 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      talaverde
      last edited by

      As a single user configuring Snort, I'm starting to see no reason to enable OpenAPPI rules. So far, it's only alerted me when I'm using an application that I already know I'm using, or accessing a site that I already know I want to.

      I was hoping it would alert me if some rogue application attempted to do something nefarious. I've seen nothing of the sort. Is this feature simply for teams to monitor certain generic browsing? As a single user (and maybe a girlfriend or two), should I disable Snort OPENAPPI rules? Thanks!

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        See my reply to you similar question here. To repeat the answer from there, "no, there is really no need to use the OpenAppID rules in a home network".

        As you surmised, those rules are primarily aimed at identifying various traffic types and are not designed to detect and stop malicious software. Mostly they are to help IT Security admins enforce corporate computing policies such as no or limited access to social media during work hours and other similar policies.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.