ClearOS Bug Tracker


View Issue Details Jump to Notes ] Issue History ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0000609ClearOSapp-intrusion-prevention - Intrusion Preventionpublic2012-05-15 04:432019-03-05 03:27
ReporterNickH 
Assigned To 
PrioritynormalSeverityfeatureReproducibilityalways
StatusclosedResolutionwon't fix 
PlatformOSOS Version
Product Version6.2.0 Updates 
Target VersionFixed in Version 
Summary0000609: Need method of specifying snortsam block rules
DescriptionAs there are no snort rules with fwsam elements provided in 6.2 it effectively makes snortsam redudant unless a way is provided to manually enter the blocking rules. I believe the IPS screen should be changed to allow you to enter text into sid-block.map. You should be able to enter a rule number which then appears on screen so you can determine whether you want to block the source or destination. You then need to be able to specify src or dst and the blocking period.
TagsNo tags attached.
Attached Files

- Relationships
related to 0000203closed Allow end user the ability to override which rules should be whitelisted 
related to 0000611closeduser2 Apply intrusion protection rules for GPL rule set 

-  Notes
(0000510)
user2
2012-05-15 08:25

Tracker 0000611 will add the fwsam rules to GPL rule set, so that will help a tiny bit.

Fundamentally, the GPL IDS/IPS system in the Community Edition is old and in some ways *worse* than nothing. The GPL rules:

- are 5+ years old
- provide 1,100-ish rules (compared to 13,000+ with the ClearCenter add-on)
- are almost static (changes are rare)
(0010381)
NickH (developer)
2019-03-05 03:27

Have to rely on IDS updates

- Issue History
Date Modified Username Field Change
2012-05-15 04:43 NickH New Issue
2012-05-15 08:00 user2 Relationship added related to 0000203
2012-05-15 08:01 user2 Relationship added related to 0000611
2012-05-15 08:25 user2 Note Added: 0000510
2012-05-15 08:25 user2 Status new => confirmed
2019-03-05 03:27 NickH Note Added: 0010381
2019-03-05 03:27 NickH Status confirmed => closed
2019-03-05 03:27 NickH Resolution open => won't fix