ClearFoundation Tracker - ClearOS
View Issue Details
0000609ClearOSapp-intrusion-prevention - Intrusion Preventionpublic2012-05-15 04:432019-03-05 03:27
NickH 
 
normalfeaturealways
closedwon't fix 
6.2.0 Updates 
 
0000609: Need method of specifying snortsam block rules
As there are no snort rules with fwsam elements provided in 6.2 it effectively makes snortsam redudant unless a way is provided to manually enter the blocking rules. I believe the IPS screen should be changed to allow you to enter text into sid-block.map. You should be able to enter a rule number which then appears on screen so you can determine whether you want to block the source or destination. You then need to be able to specify src or dst and the blocking period.
No tags attached.
related to 0000203closed  Allow end user the ability to override which rules should be whitelisted 
related to 0000611closed user2 Apply intrusion protection rules for GPL rule set 
Issue History
2012-05-15 04:43NickHNew Issue
2012-05-15 08:00user2Relationship addedrelated to 0000203
2012-05-15 08:01user2Relationship addedrelated to 0000611
2012-05-15 08:25user2Note Added: 0000510
2012-05-15 08:25user2Statusnew => confirmed
2019-03-05 03:27NickHNote Added: 0010381
2019-03-05 03:27NickHStatusconfirmed => closed
2019-03-05 03:27NickHResolutionopen => won't fix

Notes
(0000510)
user2   
2012-05-15 08:25   
Tracker 0000611 will add the fwsam rules to GPL rule set, so that will help a tiny bit.

Fundamentally, the GPL IDS/IPS system in the Community Edition is old and in some ways *worse* than nothing. The GPL rules:

- are 5+ years old
- provide 1,100-ish rules (compared to 13,000+ with the ClearCenter add-on)
- are almost static (changes are rare)
(0010381)
NickH   
2019-03-05 03:27   
Have to rely on IDS updates