当前位置:网站首页>Pfsense and snorby
Pfsense and snorby
2022-04-21 16:37:00 【Sword-heart】
0x00、 background
Hacker attacks are inevitable , I'm always floating in the rivers and lakes , There is no one who is not black ( No one can say that their network is absolutely safe ). What if you get hacked ??? It must be the first time to fix the loophole and clear the back door ! How to fix the vulnerability ??? The loophole is there again ??? This is the time to study IDS People come out :
IDS: Full name: intrusion detection system . Professionally speaking IDS Is to follow a certain security policy , Through soft 、 Hardware , To the network 、 Monitor the operation of the system , Find out as many attacks as possible 、 The act or result of an attack , To ensure the confidentiality of network system resources 、 Integrity and availability .
IPS: Than IDS The taller one is IPS,IPS The full name is intrusion prevention system .IDS It's finding that you don't move ,IPS Is in IDS After discovering the attack attempt or behavior , Take action .
0x01 Pfsense&Snorby brief introduction
pfSense It's based on FressBSD, Open source version customized for firewall and router functions . It is installed on the computer and exists as a firewall and router in the network , And known for its reliability , And provide features that often only exist in expensive commercial firewalls ( Such as vpen、IDS、IPS).
Snorby It's a Ruby on Rails Of Web Applications , Network security monitoring and current popular intrusion detection system (Snort Project Suricata and Sagan) The interface of . The goal of the project is to create a free , Open source and competitive network monitoring applications , For private and business use .
0x02 Snorby Installation and deployment of
First, set the installation source ( To use epel Source )
Snorby git Official website https://github.com/Snorby/snorby
Here's how to install , I won't go on and on .
See here for detailed installation :http://hi.baidu.com/huting/item/7a60eb725e66cb206e29f6b8
( Just install the first one .)
ad locum snorby Just analyze the data , Don't grab data , Grab data from pfsense Inside Suricata To grab . The captured data is saved to snorby Of the host server mysqld in ,snorby By calling native mysql Analyze the data in the database .
therefore Snorby Just put the server in pfsense Where you can visit .
Can I send it to the Internet ??? It should be OK , I didn't try here .
After installed , as follows :( Default user name :[email protected], password :snorby)

Failed to re upload and cancel the transfer
Click on it Settings, Here is a time setting ( It's important to pay attention to this , The wrong time is troublesome )

Failed to re upload and cancel the transfer
The next one 500000 It's a very important parameter .( This is a peak )

Failed to re upload and cancel the transfer
0x03 pfsense Deployment and configuration of
Pfsense The installation of... Will not be introduced here , The Internet is full of .
Pfsense It's a firewall. It must be deployed at the boundary of the network ! There's nothing to say about this .
A. Download and install Suricata software package
System->Packages, Here's the picture :
Failed to re upload and cancel the transfer

Failed to re upload and cancel the transfer
Failed to re upload and cancel the transfer Be careful : Before doing this, set up dns, Otherwise, the domain name cannot be resolved , You can't download .
B. Global configuration (Global Settings)
After installation , stay Services Find Suricata, Configure it basically .
The interface is as follows

Failed to re upload and cancel the transfer
We started with Global Settings( Global settings ) Make basic settings , The global settings are divided into three parts .
1. Download rules

Failed to re upload and cancel the transfer
There should be four options , The second and third is to code Of .
I don't know whether to apply for money , I haven't tried here .
2. Is the update setting of the rule
Failed to re upload and cancel the transfer
I set it here once a week .
3. General Settings

Failed to re upload and cancel the transfer
Here is a key setting .
Remove Blocked Hosts Interval What I set up here is 15 minute , The default is NEVER.
What does this mean ?? In fact, this involves what will be mentioned later IPS, When IPS When a threat is found, the target will be added to Blocked, stay Blocked Inside ip The address will not be allowed to pass through the firewall .
I set up here 15 minute , That is to say 15 Clean up once Blocked Inside ip Address .
C. Other settings
Download rule library
Failed to re upload and cancel the transfer
It's already set up , Click here Check, Download rule file .
pass lists( Here is a white list )

Failed to re upload and cancel the transfer
Not much here , As mentioned below IPS I'm talking about this .
0x04 Pfsense+Snorby==IDS&IPS
Enable IDS function Pfsense Key configuration Add monitoring network card Failed to re upload and cancel the transfer
I only have two network cards here , I chose WAN, Internet access .( Check the box above )

Failed to re upload and cancel the transfer
Set up Iface Categories
Failed to re upload and cancel the transfer
here , I choose all , Then save .( You can choose according to your own needs ) Set up Iface Rules

Failed to re upload and cancel the transfer
Choose here Auto-Flowbit Rules( Automatic forwarding rules ), Then apply .
Set up iface Barnyard2( The key )
Failed to re upload and cancel the transfer
The one below enables mysql Is the key , Fill in here Snorby On the server mysql Information about
( Be careful :mysql To enable remote access , Each page above is configured once , want save once )
Basic IDS Configuration is complete , Here's the picture .
Failed to re upload and cancel the transfer
Click the red fork above to start .
The effect after startup .

Failed to re upload and cancel the transfer
If it works , stay snorby You can see the effect above , The renderings are as follows :
Failed to re upload and cancel the transfer
Let me scan it to see the effect , I use nmap Gently sweep down

Failed to re upload and cancel the transfer
I got it in the virtual machine , That's quite a card !!!!!!
It 's bullshit ! I can see directly that you use nmap Scanning .
Failed to re upload and cancel the transfer
Enable IPS function
stay WAN Settings There's a Alert Settings, Here's the picture :
Failed to re upload and cancel the transfer
Select save after setting , And then restart Suricata take effect .
The second hook is very domineering , Discover sth ip There are dangerous , Directly disconnect all from this ip The connection of .
IPS Here we focus on the setting of the white list
First step 、 Set up aliases
Firewall Below Aliases( Add... Yourself )
Failed to re upload and cancel the transfer
The second step 、 Set up Pass Lists
Failed to re upload and cancel the transfer
Failed to re upload and cancel the transfer
Save,
stay WAN Settings Set it up inside

Failed to re upload and cancel the transfer
Click save , restart Suricata take effect .
There is one last setting , It's sealed ip When to unseal .
As mentioned above Global Settings Inside General Settings.
Failed to re upload and cancel the transfer
The setting here is 15 minute .
That is to say 15 Minutes later , Sealed ip Automatically unsealed .
explain : The purpose of this paper is , You can configure it according to your own needs . The article is not very detailed , If you write in detail , It's estimated that 20 Incoming page .
This article comes from the dark cloud knowledge base , This image is for the convenience of your study and research , The copyright of this article belongs to Wuyun knowledge base !
版权声明
本文为[Sword-heart]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204211632370878.html
边栏推荐
- What are the mobile phone hardware
- Add release configuration in clion
- ES6 how to determine whether an array is repeated
- Teach you how to do orb slam3 with oak-d and ROS noetic based on LXD
- Mini LED有哪些优势
- 巴比特副总裁马千里:元宇宙时代NPC崛起,数字身份协议或成为入口级产品丨2022元宇宙云峰会
- What are the mainstream types of mobile phone screens at present
- Invalid bound statement (not found)问题解决
- How does PHP convert negative numbers to positive integers
- 启动Redis的过程
猜你喜欢

Are you sure you don't want to see it yet? Managing your code base in this way is both convenient and worry free

Use of Arthas tunnel

云呐:机房资产管理系统web版,设备资产信息管理的应用

elmentUI下拉框实现全部功能

哪种耳机戴着耳朵不痛?不入耳佩戴的骨传导耳机

2022 number two real problem

【面试普通人VS高手系列】能谈一下CAS机制吗?

iOS开发面试攻略(KVO、KVC、多线程、锁、runloop、计时器)

Invalid bound statement (not found)问题解决

SIGIR 2022 | reinforcement learning recommendation system from the perspective of prompt
随机推荐
程序设计天梯赛L3-28 森森旅游(想到multiset就算成功)
程序设计天梯赛L3-29 还原文件(dfs就过了,离离原上谱)
Pfsense和Snorby
Want to make a fortune by "leaking data"? What a punishment
What is the anti correlation principle? How to choose the anti Association fingerprint browser? What are the criteria?
云呐:资产密集型企业固定资产管理系统的基本功能特点
OJ每日一练——逆序整数
Online dictionary website
OJ每日一练——最大公约数与最小公倍数
直播带货、送外卖、做货运,航空公司靠副业“回血”
想靠“泄露数据”来发家?真刑啊
OJ daily practice - maximum common divisor and minimum common multiple
手机里的NPU可以起到什么作用
How many skills are necessary to master automated testing?
OJ每日一练——字符个数
2018-8-10-use-resharper-features
打卡:4.21 C语言篇 -(1)初识C语言 - (11)关键字register,#define定义的宏
MySQL queries whether a field contains Chinese characters
RAM运行内存是什么
Multi core and multi CPU programming -- task scheduling