IPS & blocking

IPS & blocking

IPS & blocking
IPS & blocking
a week ago
Model: ER8411  
Hardware Version: V1
Firmware Version: 1.3.6

I'm fairly new to the Omada ecosystem having migrated from a Netgate switch that died and a handful of lower-end Unifi switches, so I'm still trying to learn and apply what I know from other platforms.  I'm using the above device as a gateway to a small-ish HOME network where I host about a dozen services for friends & family.  I've enabled IDS/IPS and configured it for HIGH security level.  I might simply not be fully understanding the whole IDS/IPS process in Omada, but if I look at the Threat Management tab in the Omada dashboard, I see lots of things like "misc-attack" from DShield, low-severity policy-violations, etc.  Are these indications that the controller has taken action and BLOCKED those attacks and policy violations?  Or, do I need to explicitly do a manual action to add those IP addresses identified into the Block List tab?  If so, why is the block list so severely limited in capacity (like I can only seem to select those DShield results and select "block" to add them to the Block List tab).  If I DO have to explicitly add those IP addresses to the block list, is there a way to increase the number of block list entries?  I think if I try to add more than 20 or so, I start getting alerts that the block list is full.

If it's simply my misunderstanding about how the IDS/IPS stack works in Omada, can anyone point me to any sort of good documentation so I can learn more?  Googling doesn't help much and always seems to just point be back to the forums here, for specific issues others have posted about.

 

Thanks in advance!

I'm fairly new to the Omada ecosystem having migrated from a Netgate switch that died and a handful of lower-end Unifi switches, so I'm still trying to learn and apply what I know from other platforms.  I'm using the above device as a gateway to a small-ish HOME network where I host about a dozen services for friends & family.  I've enabled IDS/IPS and configured it for HIGH security level.  I might simply not be fully understanding the whole IDS/IPS process in Omada, but if I look at the Threat Management tab in the Omada dashboard, I see lots of things like "misc-attack" from DShield, low-severity policy-violations, etc.  Are these indications that the controller has taken action and BLOCKED those attacks and policy violations?  Or, do I need to explicitly do a manual action to add those IP addresses identified into the Block List tab?  If so, why is the block list so severely limited in capacity (like I can only seem to select those DShield results and select "block" to add them to the Block List tab).  If I DO have to explicitly add those IP addresses to the block list, is there a way to increase the number of block list entries?  I think if I try to add more than 20 or so, I start getting alerts that the block list is full.

If it's simply my misunderstanding about how the IDS/IPS stack works in Omada, can anyone point me to any sort of good documentation so I can learn more?  Googling doesn't help much and always seems to just point be back to the forums here, for specific issues others have posted about.

 

Thanks in advance!

  0      
  0      
#1
Options
4 Reply
Re:IPS & blocking
a week ago

Hi  @MadOtis 

Thanks for the feedback.

May I confirm if you use the standalone or Controller mode for your ER8411?

By the way, can you provide any configuration screenshots regarding the IPS/IDS? Such as the limit error when it exceeds 20?

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#2
Options
Re:IPS & blocking
a week ago

  @Hank21 

 

Hank21 wrote

Hi  @MadOtis 

Thanks for the feedback.

May I confirm if you use the standalone or Controller mode for your ER8411?

By the way, can you provide any configuration screenshots regarding the IPS/IDS? Such as the limit error when it exceeds 20?

 

I'm running the on-prem Omada controller software (Not the hardware OC-200/300) as a docker container on one of my hosts.   And my apologies, the block list seems to be limited to 40 entries.  If I try to add more, it pops up this alert:

 

Limit popup

 

If it's helpful, here is how IDS/IPS is configured:
Config

 

If I go to the Threat Management tab and filter on, for example, All alerts reported by DShield only, select them and click the Block link at the top of the list, it refuses to add any more items to the block list and displays the blocked popup shown above.

  0  
  0  
#3
Options
Re:IPS & blocking
Friday
Also, and I'm not sure if this matters or not, I'm on the latest firmware release across all Omada gateways, switches, and APs, but I still can't make much progress beyond the block list limit.
  0  
  0  
#4
Options
Re:IPS & blocking
Tuesday

Hi  @MadOtis 

To help assist and streamline the identification of the behavior, we recommend sending an email to forumsupport.usa@tp-link.com with the following information:

Subject: [Forum Escalation][ID 860026] 
Forum Nickname: 
Thread URL:  
Model&Version: 
Description: 
Any Other Relevant Information (Logs, Config Files, Images, etc.): 

Once sent, a ticket will be created in our support system, and a member of the team will follow up to gather more information or troubleshoot a cause.

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#5
Options