Fusion 2.5G IDS/IPS
Hi there,
Last week I installed a Fusion 2.5G together with a SG2008P V3.30 to replace and improve my network setup. I had a container running the gateway to configure my to EAP610's before.
I've enabled IDS and IPS since a few days, but I when I browse to the threat management map I don't have a single thread visible. I even tried to do a remote nmap on my public IP to see if that would trigger something.
My config is as follows:

With the following categories enabled:

The threat management map stays empty:

Is there some way to see if it's working at all?
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
@MR.S thanks for that one. It didn't seem to trigger any events, but enabling the user agent category did trigger an event for the Steam user agent "ET USER_AGENTS Steam HTTP Client User-Agent".
- Copy Link
- Report Inappropriate Content
It does function on fusion, but, IDS/IPS is quite dependant on your ISP as well. Your ISP may already be filtering the same things upstream - especially if you are behind CGNAT
Do you have a fixed static public IP or is it dynamic?
On the three ISPs i use i tend to find IDS/IPS only pick up things -rarely- outgoing from my lan as everything is already filtered upstream on the incoming side.
Also, if you have incoming WAN IN acls to block stuff they may be blocking things before it hits the IPS engine
- Copy Link
- Report Inappropriate Content
@GRL thanks for the reply.
Yeah, could very well be that my ISP is blocking specific traffic.
I'm behind a dynamic IP.
I don't have any ACLs on the WAN.
In any case, I have DShield active. I went to dshield's block list and tried to ping an ip that should fall in the first subnet mentioned in the file. Ping returned fine, so at least ICMP echo towards DShield listed subnets isn't blocked by the IPS.
I'll try to enable a listener on my public IP and see if nmap will pick it up when doing an external scan, but I'm fairly certain my ISP won't block it. And I would expect IDS/IPS to pick that up.
Otherwise I'll just have an ssh server up for a day or something that should for sure show something?
- Copy Link
- Report Inappropriate Content
To test IDS and IPS run this command from your computer
curl -A "BlackSun" example,com
run more than once,
wait 5 min and look at the log.
- Copy Link
- Report Inappropriate Content
@MR.S thanks for that one. It didn't seem to trigger any events, but enabling the user agent category did trigger an event for the Steam user agent "ET USER_AGENTS Steam HTTP Client User-Agent".
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 204
Replies: 4
Voters 0
No one has voted for it yet.
