Suricata IDS/IPS Installation on Opnsense - Virtual Lab Building Series: Ep3

  Рет қаралды 39,719

LS111 Cyber Security Education

LS111 Cyber Security Education

Күн бұрын

Пікірлер: 94
@ls111cyberEd
@ls111cyberEd 2 жыл бұрын
A quick note, at 2:02 in the video I mention disabling hardware checksum offloading, TCP segmentation offloading and large receive offload and then proceed to uncheck the checkboxes. This is my error and they should remain checked. Thanks to those in the comments that also pointed this error out.
@TheCarlosm89
@TheCarlosm89 Жыл бұрын
After I copy my xml file to opnsense, it does not show in the download list. Any ideas how to fix this?
@ViszlaBoss
@ViszlaBoss 11 ай бұрын
How do i get back to my WEBgui now? Didnt see your correction now cannot get to the WEBgui?
@steveyoung5848
@steveyoung5848 9 ай бұрын
@@ViszlaBoss I may have experienced the same thing. It went unresponsive and I had to delete the opnsense vm and start from scratch.
@theprettybond159
@theprettybond159 8 ай бұрын
@@steveyoung5848 You can just restore factory defaults and reset the ip of the wan and lan, full deletion isnt needed
@nickquik
@nickquik 6 ай бұрын
​@ViszlaBoss it would be responsible for him to speak on this since following his tutorial messed it up
@melvindrake22
@melvindrake22 Жыл бұрын
great lab and very informative videos. I've been following this series and everything is working as intended. Once completed I'll tear it all down and build it again from my notes. Thanks for taking the time to do this and explain in detail.
@leckovich
@leckovich 7 ай бұрын
could you find the rules files?
@urfriendsamir
@urfriendsamir 11 ай бұрын
Going through this right now! Got the rule to work and pick up the reconnaissance scan! This will serve as a worthy project in my portfolio! Thank you!
@leckovich
@leckovich 7 ай бұрын
did you find the rule files?
@roxasdracun8661
@roxasdracun8661 15 күн бұрын
@@leckovich I kinda confuse myself as he just skips steps assuming we know how to do stuff but most im seeing the rules like file is under /var/lib/suricata/rules/suricata.rules Which a bunch of rules have already been created by preset. As for us creating one and if we need to configure suricate to be able to other stuff I am quite lost. Following this video right now as kinda makes a bit more sense: kzbin.info/www/bejne/i4muk5tmn7WDpsk
@lorneshantz4892
@lorneshantz4892 Жыл бұрын
I think I have found a conflict. At 2:25 you speak of unchecking these. I think that is backwards. 1. When I tried to uncheck them, things broke. So I did some research and Opnsense specifically says: When using IPS mode make sure all hardware offloading features are disabled in the interface settings (Interfaces ‣ Settings) So if you read carefully what it says, being checked is disabled. Unchecking does the opposite of what you are trying to do. UPdated: Sorry! I see you have posted a correction. I missed that.
@nickquik
@nickquik 6 ай бұрын
My gui disappeared after doing that and now I can't access my router 😭
@p4r4d0xhacks
@p4r4d0xhacks 6 ай бұрын
Just loving the content. Learned so much in just 2 videos.
@emeraldsoul6200
@emeraldsoul6200 2 жыл бұрын
As soon as I apply the IDS settings, the connection on OPNsense like: "netnap_transmit ... drop mbuf that needs checksum offload
@zoomingby
@zoomingby Жыл бұрын
Suggestion: 1:00 when making statements like "IDS will detect anomalies" which is somewhat vague and opaque, can you give us an example how it would for a typical user or a use case or a scenario and what might happen if an IDS wasn't installed? Using an example of how it would protect us or situations where we'd be detected makes it much easier to grasp the concept.
@viteks.100
@viteks.100 4 ай бұрын
Having the strange feeling when I don't know if I like you or I hate you! Looks like new version of Opnsense kinda buggy , and needed to install older version. Now after all it's working correctly, thank you very much.
@skullcrusher4307
@skullcrusher4307 11 ай бұрын
Hello! I enjoyed watching the video. I have a question: will this work if I have high availability set up? Will I need to do the configurations on both firewalls? Cheers!
@ls111cyberEd
@ls111cyberEd 11 ай бұрын
Hi, Thanks for watching, The short answer is yes, you will need to make sure that when you configure your HA settings, under the XMLRPC sync, select the "intrusion detection" option and it should sync the settings between the master and backup firewall.
@catlmarc9618
@catlmarc9618 2 жыл бұрын
Great Videos. Glad I found your channel
@WarThunderista
@WarThunderista 22 күн бұрын
Everything works fine Thanks 👌
@davidaliata8719
@davidaliata8719 Жыл бұрын
Thank you for this videos, they are very informative. Can you please share the two custom files ?
@hanshopman3487
@hanshopman3487 Жыл бұрын
Well, good course, but got stuck in ep3 when activating IDS and disabling the ofload. OPNSense 23.7 console says "drop mbuf that needs checksum of fload". The webinterface stopped responding. I wished i had read the pinned comment before watching the video, because now i am locked out of OPNSense. Restoring yesterday backup fixed the issue.
@abodawead9039
@abodawead9039 Жыл бұрын
Great job man
@magueritemichima6818
@magueritemichima6818 8 ай бұрын
hello , great video , so i will like to know did you and install suricata ids on opensense ? in your video you just import rules from kali to openses, you also talk about proofpoint free rules , how can we install this modules on opensense ?
@Skylinar
@Skylinar 2 жыл бұрын
2:16 You disabled the checkboxes within Interfaces > Settings but if you take a look to the infotext it shows that: Checking this option will disable hardware checksum offloading. In my understanding this would mean you have enabled it or am I wrong?
@szubert
@szubert 2 жыл бұрын
Yes, he turned it on instead to turn it off ;) Here is a video from closest to source of Suricata: kzbin.info/www/bejne/laqsomZ9gpmaoKM
@szubert
@szubert 2 жыл бұрын
Also in "home networks" lot of sources are telling that you need put there a WAN subnet, not only the LAN subnet.
@xXxCobraCommanderxXx
@xXxCobraCommanderxXx 2 жыл бұрын
I agree, he did it backward.
@roxasdracun8661
@roxasdracun8661 18 күн бұрын
Kinda confuse , the rule was for suricata was there didnt show how to create as well with the pro telemetry thing not sure if we need to create another VM with it or how to integrate to current OPNSENSE
@Morfoz13
@Morfoz13 Жыл бұрын
Thanks for this great tutorial! Should I also modify any of the rules in the Rule tab? Mos of them are set to alert, should I change them to drop?
@ls111cyberEd
@ls111cyberEd Жыл бұрын
Thanks for watching! The choice is entirely yours based on your unique requirements on how you wish to set this up. If you choose to drop the packet it will stop processing the packet and alert. If you choose just to alert, the packet will still be allowed and only an alert will be sent, for further analysis.
@trevorfadale7237
@trevorfadale7237 Жыл бұрын
Has anyone figured out the import of the rule into opnsense??
@osmaster3327
@osmaster3327 2 жыл бұрын
Could you share the rules file please?
@isee-9625
@isee-9625 3 ай бұрын
I have an issue with Suricata not show alerts in the "Alerts" view of the web interface I have reviewed all the materials that I could find a and still can't get this to work properly
@delodare5770
@delodare5770 2 ай бұрын
i have same problem
@FTLN
@FTLN 2 жыл бұрын
Why are you enabling Hardware checksum / Hardware TCP / Large receive offloading ?? Documentation clearly states thes should remain disable.....
@alexeyiah89
@alexeyiah89 11 ай бұрын
i followed this for the past 3 days i can't get the firewall to generate any alert after the port scan, is there anything i'm missing?
@cleon5950
@cleon5950 Ай бұрын
9 months late but the > in the rules should be ->
@scottjmagee
@scottjmagee 2 жыл бұрын
Awesome, thanks!
@dkcarey1
@dkcarey1 2 жыл бұрын
What’s the difference between using this and Zenarmor? Which is better, or can you use them both side by side?
@ls111cyberEd
@ls111cyberEd 2 жыл бұрын
Hi there, Zenarmor basically uses Suricata in the background to achieve the same result. Zenarmor is generally easier to setup and use. As a side note, if you try to run Zenarmor and this at the same time you will get a error. You will need to disable this firstly, then install Zenarmor. If you have not already seen I have a video covering this: kzbin.info/www/bejne/iISxhmCXit-ZnaM
@dkcarey1
@dkcarey1 2 жыл бұрын
@@ls111cyberEd thank you
@MarekCezaryWojtaszek
@MarekCezaryWojtaszek Жыл бұрын
In 8:06 you mention that you will leave information in the description about a plugin needed for the pro rules but I could not find it. Could you please advise?
@ls111cyberEd
@ls111cyberEd Жыл бұрын
Thanks for watching. The link is included in the description under ET Pro Telemetry, but for your convenience, I have included it here shop.opnsense.com/product/etpro-telemetry/ All the links to get the PRO plugin working and more info about ProofPoint can be found there.
@MarekCezaryWojtaszek
@MarekCezaryWojtaszek Жыл бұрын
@@ls111cyberEd Thank you! Actually I figured it out just after posting my question :). Anyway, great video as all other materials from your channel. Adding to my favorites :)
@ls111cyberEd
@ls111cyberEd Жыл бұрын
Thanks, @MarekCezaryWojtaszek, I appreciate the support!
@funmemes5915
@funmemes5915 9 ай бұрын
Great Stuff
@mytime2016
@mytime2016 2 ай бұрын
Hi bro my rules are enable but when u click on download and update rules still does not install
@TahmaseebZaman
@TahmaseebZaman 2 жыл бұрын
does Enabling the IDS/IPS feature reduce the link speed in this case? if so how much does it reduce? I know Ubiquiti UDM Pro link speed goes down to 3.5gbps from 10gbps, at least that's what it says on the specification. so I'm guessing something similar will happen here too.
@ls111cyberEd
@ls111cyberEd 2 жыл бұрын
Yes your are correct, anywhere that you apply additional processing/filtering of traffic on your network you will note throughput degradations regardless of the manufacturer, software or appliance used. As to how much in this case I cant give you an exact amount because it will be dependent on things like hardware variables and number of users on the network. for e.g. If I install OPNSense on high-end hardware with a powerful CPU and Intel based NICs naturally we can expect better throughput than if we use lower-end hardware. According to the OPNSense manual their recommended hardware spec is 1.5Ghz multi-core CPU, 8GB RAM, 120GB SSD and they state a throughput range of 350-750+ Mbps with the full feature set enabled, which includes Squid Proxy, Captive Portal etc. I hope that this answer helps. 👍
@pawemaleszewski133
@pawemaleszewski133 Жыл бұрын
In my case on Zimaboard 432 and intel i350-t4 card without IDS 700mbits down 100 up. With IDS on 500 mbits down/100 mbits up. Home environment so its not even noticeable
@Abobo007
@Abobo007 Жыл бұрын
I’m stuck at getting alerts on my IDS. I’ve tried every thing I know to troubleshoot but no alert still😭😭
@armstrongnhlabatsi1925
@armstrongnhlabatsi1925 Жыл бұрын
I am facing the same issue. No alerts in my IDS
@Abobo007
@Abobo007 Жыл бұрын
@@armstrongnhlabatsi1925 I’m still stuck there tbh lol. Im hopeful to get a solution
@eliepakabilond4075
@eliepakabilond4075 Ай бұрын
Hi bro. Check your custom map rule. You might have picket http traffic instead of tcp.
@viettran3959
@viettran3959 Жыл бұрын
Daddy, in the rulesets section, the customnmap file appears. I noticed in the video that it shows both customnmap/customnmap rule, while mine only shows the customnmap rule. I cannot download them, only enable them.
@juansanjosepena4074
@juansanjosepena4074 2 жыл бұрын
great video!!
@nnekalyn4494
@nnekalyn4494 Жыл бұрын
I can't get filezilla to connect at all on port 22. Tried port 21 and the connection attempt drops due to "20 seconds of inactivity". Not sure the issue here,since i did the Nmap scan and port 22 is open. My login credentials allow me to log into OPNsense, but create an authentication error for Filezilla. Help?
@ls111cyberEd
@ls111cyberEd Жыл бұрын
Hi and thanks for watching, please double check that SSH has been enabled like I showed from 13:16 onward and that you have your listening interface set to LAN, this will automatically take care of the firewall rules for you opening that port. The reason port 21 wont work is because firstly we don't have any services listening on port 21 (FTP) and secondly the firewall will drop it since we have not told the firewall to explicitly allow it. Secure FTP (SFTP) listens on port 22. When you are in filezilla please make sure that you use sftp://x.x.x.x and the port number 22 with your OPNSense username and password, it should then connect.
@stellar369
@stellar369 8 ай бұрын
Please someone reply to this, I have enabled NAT and Intnet (2 adapters) on both Opnsense and Kali linux. Then I used WAN address from opnsense as default gateway on kali linux. Now, on my kali linux, I can work on opnsense gui but nothng else on the internet is working. Is it online or offline, does it needs Internet as well?
@SuperKkamran
@SuperKkamran Жыл бұрын
Hi, wonder if this is still active. I cannot access web gui after enabling IPS/IDS as described from lecture from 5:25. I clicked Apply and it kept spinning and after that no access. It's pinging though!
@logs4040
@logs4040 Жыл бұрын
Not what he said to do but I kept having a bunch of issues including this until I just enabled DHCP for the interface... might break things later though.
@ls111cyberEd
@ls111cyberEd Жыл бұрын
Hi and thanks for watching, nothing at this stage of the process should prevent you from accessing the firewall that comes to mind, just double-check that you have set up your home network and interfaces correctly and worst case reboot the FW and try again.
@ls111cyberEd
@ls111cyberEd Жыл бұрын
Thanks for watching, using static IP addresses or DHCP is totally your choice in this lab and if either of these options are set up correctly everything will work. I chose static IP addresses to keep everything consistent when creating this lab, DHCP being dynamic in its operation can not guarantee that same consistency.
@logs4040
@logs4040 Жыл бұрын
Thank you
@SuperKkamran
@SuperKkamran Жыл бұрын
It's updated version. The error reads' "411 netmap_transmit em0 drop mbuf that needs checksum of ...." Applied on both LAN and WAN interfaces, one by one. Before enabling IPS, it works well.
@SageN-
@SageN- 6 ай бұрын
The rule is not reflecting on the firewall what could be the issue? even after setting up the server
@eliepakabilond4075
@eliepakabilond4075 Ай бұрын
Check you custom map rule. You might have written http instead of tcp
@y.s.mcgeechen656
@y.s.mcgeechen656 4 ай бұрын
Does anyone know how to restore those 3 Hardware settings after unchecking them? I cannot login to the Web GUI
@davidedamico5321
@davidedamico5321 4 ай бұрын
you have to reset the machine trought the vm of opnsense, login and after insert 4 for favtory reset, or user one of the automatic backup using the option 13
@user-zr7kz4vs7c
@user-zr7kz4vs7c Жыл бұрын
Do I still need IPS if I don’t open ports on WAN side?
@ls111cyberEd
@ls111cyberEd Жыл бұрын
Thanks for watching! Yes, it's a good practice to monitor your outgoing or egress traffic. Just a basic example, let's say a user on your network unknowingly downloads malware or something malicious, by using an IPS/IDS on the outgoing traffic you could detect and prevent the malware from calling home for instance.
@valbuz
@valbuz 2 жыл бұрын
When i want to activate the IDS, this ends with a error: [100207] -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol http2 enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details. Is there any workaround? Thanks Pat
@ls111cyberEd
@ls111cyberEd 2 жыл бұрын
Hello Pat, I went to have a look at the ticket as advised by the message, you can have a look here: redmine.openinfosecfoundation.org/issues/4744 It seems this is just a warning at this stage and should not prevent you from completing the lab. The way I understand the ticket, it has to do with the app-layer protocol section in the suricata.yaml config file where if this section is missing in the config file, the system will automatically enable it as a workaround in versions 6.0.x of Suricata. For future versions of Suricata 7.0 (which is in the Release Candidate stage of development) they just state that this protocol section will need to be explicitly defined in the .yaml file or it wont work moving forward. Since Suricate is baked into the OPNSense firewall it will most likely be patched or upgraded before Suricata 7 moves into stable release. Hope that this answer helps!
@medidarmawan5247
@medidarmawan5247 2 жыл бұрын
Is there an ebook or blog version?
@ls111cyberEd
@ls111cyberEd 2 жыл бұрын
Hi, unfortunately not, my main focus right now is to produce video content, however, I may write about this at a later stage, you can keep a eye on my blog if you like. Link ls111.me
@MrArsalan1988
@MrArsalan1988 2 жыл бұрын
nice
@arseniobrown7744
@arseniobrown7744 Жыл бұрын
When I click Download and update rule nothing happens what should I do to fix this.
@ls111cyberEd
@ls111cyberEd Жыл бұрын
Hi, thanks for watching! Please double check that your python http server is running from the directory where you placed your rules as seen in the video at 18:40, hope that helps.
@MrIrelevant12
@MrIrelevant12 Жыл бұрын
@@ls111cyberEd I ran into this issue and it took me a while to find out why. Make sure your customnmap.xml file is correct whether that be the correct IP or the correct format. I had formatting issues in mine.
@viettran3959
@viettran3959 Жыл бұрын
@@MrIrelevant12 broo, What is the correct format? Should I use the .xml file extension?
@MrIrelevant12
@MrIrelevant12 Жыл бұрын
I just copied both files from the video, but you have to be very careful with the formatting. I just checked each line.@@viettran3959
@steveyoung5848
@steveyoung5848 9 ай бұрын
@@MrIrelevant12 Good call! I couldn't get my customnmap.xml file to serve to opnsense due to a missing / in the file! All it takes is one missing character sometimes to throw things off.
@mohammadwleed3701
@mohammadwleed3701 2 жыл бұрын
I want to contact you, is it possible?
@baskaranranujan7234
@baskaranranujan7234 Жыл бұрын
unable install filezilla on kali linus vm "Package filezilla is not available, but is referred to by another package. This may mean that the package is missing, has been obsoleted, or is only available from another source "
@nnekalyn4494
@nnekalyn4494 Жыл бұрын
had to update my kali in order to get it
@baskaranranujan7234
@baskaranranujan7234 Жыл бұрын
@@nnekalyn4494 I did unable to do let me try again
@leckovich
@leckovich 7 ай бұрын
its a shame to start a lab like this and cannot advance because rules are not available anywhere, so its imposible to continue. I wont recommend this lab, just imposible to continue
@Beyondlimits-m6f
@Beyondlimits-m6f Жыл бұрын
boring sorry
OPNsense Web Filtering/Proxy Configuration - Virtual Lab Building Series: Ep4
25:22
LS111 Cyber Security Education
Рет қаралды 36 М.
Wazuh SIEM & XDR Agent Installation - Virtual Lab Building Series: Ep9
24:41
LS111 Cyber Security Education
Рет қаралды 31 М.
Yay, My Dad Is a Vending Machine! 🛍️😆 #funny #prank #comedy
00:17
Elza love to eat chiken🍗⚡ #dog #pets
00:17
ElzaDog
Рет қаралды 19 МЛН
The Singing Challenge #joker #Harriet Quinn
00:35
佐助与鸣人
Рет қаралды 9 МЛН
Cybersecurity Architecture: Application Security
16:36
IBM Technology
Рет қаралды 73 М.
TheHive, Cortex & MISP Installation Using Docker Compose - Virtual Lab Building Series: Ep10
24:36
Top 12 Tips For API Security
9:47
ByteByteGo
Рет қаралды 118 М.
How to Integrate Wazuh & TheHive - Virtual Lab Building Series Ep: 13
14:55
LS111 Cyber Security Education
Рет қаралды 11 М.
Kubernetes Explained in 15 Minutes | Hands On (2024 Edition)
15:18
Travis Media
Рет қаралды 99 М.
Opnsense Firewall Installation - Virtual Lab Building Series: Ep2
27:09
LS111 Cyber Security Education
Рет қаралды 50 М.
TLS Handshake - EVERYTHING that happens when you visit an HTTPS website
27:59
Practical Networking
Рет қаралды 127 М.
Yay, My Dad Is a Vending Machine! 🛍️😆 #funny #prank #comedy
00:17