Hi @S-K
Thanks for posting in our business forum.
S-K wrote
@Clive_A I don't aim to have a crowdsec installation in the Omada system. I think of a connector which is able to get a set of IPs from crodsec. And then use them for example in a gateway-ACL for being blocked. At the moment the gateway itself is able to detect a handfull of possible attack patterns and the hardware won't be able to run a mature intrusion detection system. But recieving the results of an ids and blocking them at the omada gateway would be a great chance to enhance security.
Do you know whether I could achieve this (edit/update an IP Group with a huge amount of IP Addresses, about > 30.000) with CLI commands?
No. The router is not capable of adding 30,000 IP addresses to the block list. I mean each IP address, e.g. 1.2.3.4/32 an 30,000 of them.
Note that if we need to add this kind of feature to allow you to add many of IP addresses, it is not only about the connector to their server via API stuff to sync with them. (This might be easy if the memory is enough for this. But there will be new features for the Omada routers. We need to save space for future features as well as data storage.)
And we have to optimize the system for the amount of IP addresses that will be added to the system.
If that's your use case, you probably should take a look at the Deco system. It got an online sync with the security database which offers you a way to protect your network via the paid subscription.
Omada does not support any database or we plan to add any database. The best practice would be creating the CIDR to limit unwanted or harmful IP addresses. The system is a traditional pre-built one. It is not an open source like openwrt or pfsense where you can import whatever rules you want or install tools you like.
I have explained this to you and from the current situation this is a small-chance proposal. I have added this to the request pool but I am just letting you know that this is a small-chance.