ClearFoundation Tracker - ClearOS
View Issue Details
0008201ClearOSapp-intrusion-prevention - Intrusion Preventionpublic2016-05-01 06:072016-05-04 15:34
dtech 
user2 
highminorhave not tried
closedfixed 
ClearOS Community6.7.0
6.7.0 
7.2.0 Updates 
0008201: 0426 ClearSDN intrusion protection update broken
I have two ClearOS 6.7 servers at different locations with Intrusion Protection subscriptions, and neither one is showing any IP addresses in the Blocked List. Both servers stopped blocking hosts on April 27 at about 4:00 PM EST. As it happens this is right about the time that the 0426 ClearSDN intrusion protection update was automatically applied.

From another user:

I confirm. I'm using ClearOS Home Edition and since the last intrusion-prevention update no more IP banned before that I had a lot of banned IP.
A quick look in /etc/snort.d/rules/clearcenter, only one alert activate snortsam.

What I did:
cat /etc/snort.d/rules/clearclenter/*.rules | grep fwsam:

and this is what I get:

alert tcp $EXTERNAL_NET any -> $HOME_NET 995 (msg:"ET SCAN Rapid POP3S Connections - Possible Brute Force Attack"; flags: S,12; threshold: type both, track by_src, count 30, seconds 120; reference:url,doc.emergingthreats.net/2002993; classtype:misc-activity; sid:2002993; rev:6; fwsam: src, 1 day

Every rules who normaly should activate snortsam miss this statement "fwsam: src, 1 day" at the end of each alert.
Forum thread: https://www.clearos.com/clearfoundation/social/community/banned-ip-list-empty [^]
No tags attached.
Issue History
2016-05-01 06:07dtechNew Issue
2016-05-02 10:20user2Note Added: 0003161
2016-05-02 10:20user2Statusnew => resolved
2016-05-02 10:20user2Fixed in Version => 7.2.0
2016-05-02 10:20user2Resolutionopen => fixed
2016-05-02 10:20user2Assigned To => user2
2016-05-04 15:34user2Statusresolved => closed
2016-05-04 15:34user2Fixed in Version7.2.0 => 7.2.0 Updates

Notes
(0003161)
user2   
2016-05-02 10:20   
A new rule set will be released before the end of the day.