Fusion 2.5G IDS/IPS

Fusion 2.5G IDS/IPS

Fusion 2.5G IDS/IPS
Fusion 2.5G IDS/IPS
a week ago - last edited 41 minutes ago
Model: Fusion 2.5G  
Hardware Version: V1
Firmware Version: 1.0.30

Hi there,

 

Last week I installed a Fusion 2.5G together with a SG2008P V3.30 to replace and improve my network setup. I had a container running the gateway to configure my to EAP610's before.

 

I've enabled IDS and IPS since a few days, but I when I browse to the threat management map I don't have a single thread visible. I even tried to do a remote nmap on my public IP to see if that would trigger something.

 

My config is as follows:

 

 

With the following categories enabled:

 

The threat management map stays empty:

 

Is there some way to see if it's working at all?

  0      
0
#1
Options
1 Accepted Solution
Re:Fusion 2.5G IDS/IPS-Solution
Saturday - last edited 41 minutes ago

  @MR.S thanks for that one. It didn't seem to trigger any events, but enabling the user agent category did trigger an event for the Steam user agent "ET USER_AGENTS Steam HTTP Client User-Agent".

 

Recommended Solution
  0  
0
#5
Options
4 Reply
Re:Fusion 2.5G IDS/IPS
Friday - last edited Friday

  @bcdbcd 

 

It does function on fusion, but, IDS/IPS is quite dependant on your ISP as well.  Your ISP may already be filtering the same things upstream - especially if you are behind CGNAT

 

Do you have a fixed static public IP or is it dynamic?  

 

On the three ISPs i use i tend to find IDS/IPS only pick up things -rarely- outgoing from my lan as everything is already filtered upstream on the incoming side.

 

Also, if you have incoming WAN IN acls to block stuff they may be blocking things before it hits the IPS engine

  0  
0
#2
Options
Re:Fusion 2.5G IDS/IPS
Friday

  @GRL thanks for the reply.

 

Yeah, could very well be that my ISP is blocking specific traffic.

I'm behind a dynamic IP.

 

I don't have any ACLs on the WAN.

 

In any case, I have DShield active. I went to dshield's block list and tried to ping an ip that should fall in the first subnet mentioned in the file. Ping returned fine, so at least ICMP echo towards DShield listed subnets isn't blocked by the IPS.

 

I'll try to enable a listener on my public IP and see if nmap will pick it up when doing an external scan, but I'm fairly certain my ISP won't block it. And I would expect IDS/IPS to pick that up.

Otherwise I'll just have an ssh server up for a day or something that should for sure show something?

  0  
0
#3
Options
Re:Fusion 2.5G IDS/IPS
Saturday

  @bcdbcd 

 

To test IDS and IPS run this command from your computer

 

curl -A "BlackSun" example,com
 

 

 

run more than once, 

 

wait 5 min and look at the log.

 

  0  
0
#4
Options
Re:Fusion 2.5G IDS/IPS-Solution
Saturday - last edited 41 minutes ago

  @MR.S thanks for that one. It didn't seem to trigger any events, but enabling the user agent category did trigger an event for the Steam user agent "ET USER_AGENTS Steam HTTP Client User-Agent".

 

Recommended Solution
  0  
0
#5
Options

Information

Helpful: 0

Views: 204

Replies: 4