Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Filter and "not dropped"

    IDS/IPS
    2
    4
    109
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      justme2 last edited by

      All,

      It would be helpful to have a checkbox selection for "Not Dropped" in the filtering section for Suricata/Snort. Particuarly of interest when the engine is "INLINE". Various rules may be "alert" (instead of drop) - being able to quickly review those to see if additional tweaks/tunings (conversion to "drop") are required.

      Thanks!

      bmeeks 1 Reply Last reply Reply Quote 0
      • bmeeks
        bmeeks @justme2 last edited by

        @justme2 said in Filter and "not dropped":

        All,

        It would be helpful to have a checkbox selection for "Not Dropped" in the filtering section for Suricata/Snort. Particuarly of interest when the engine is "INLINE". Various rules may be "alert" (instead of drop) - being able to quickly review those to see if additional tweaks/tunings (conversion to "drop") are required.

        Thanks!

        Are you talking about on the RULES tab? If so I can add that to my TODO list for a future update.

        J 1 Reply Last reply Reply Quote 0
        • J
          justme2 @bmeeks last edited by

          @bmeeks

          Actually, was thinking: Services -> <IDS/IPS Engine> -> Alerts

          The ability to remove drops while doing regular spot checking and see what triggered an alert (not a "drop") - has become more interesting.

          For: Services -> <IDS/IPS Engine> -> Interfaces -> <Interface> -> Rules, a means to reduce the list via a valid action type would be most appreciated.

          Thanks!

          bmeeks 1 Reply Last reply Reply Quote 0
          • bmeeks
            bmeeks @justme2 last edited by

            @justme2 said in Filter and "not dropped":

            @bmeeks

            Actually, was thinking: Services -> <IDS/IPS Engine> -> Alerts

            The ability to remove drops while doing regular spot checking and see what triggered an alert (not a "drop") - has become more interesting.

            For: Services -> <IDS/IPS Engine> -> Interfaces -> <Interface> -> Rules, a means to reduce the list via a valid action type would be most appreciated.

            Thanks!

            Oh, I see. It's not hard to add the feature to that page either. I'll put that on the TODO list as well.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post

            Products

            • Platform Overview
            • TNSR
            • pfSense Plus
            • Appliances

            Services

            • Training
            • Professional Services

            Support

            • Subscription Plans
            • Contact Support
            • Product Lifecycle
            • Documentation

            News

            • Media Coverage
            • Press
            • Events

            Resources

            • Blog
            • FAQ
            • Find a Partner
            • Resource Library
            • Security Information

            Company

            • About Us
            • Careers
            • Partners
            • Contact Us
            • Legal
            Our Mission

            We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

            Subscribe to our Newsletter

            Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

            © 2021 Rubicon Communications, LLC | Privacy Policy