Old 06-27-2011, 11:59 AM   #1 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,612
dmorris is on a distinguished road
Default Intrusion Prevention and 9.0

We made several performance improvements and overall cleanups to the product in 9.0, especially to "matchers" which match rules/strings to port, address, usernames, etc. This isn't a change to Intrusion Prevention specifically, but it does effect Intrusion Prevention heavily along with other rule-based apps like Firewall, Policy Manager, etc.

This has really improved the performance of Intrusion Prevention so as a result you might notice that it is matching a lot more traffic and signatures than it did in previous versions.
This is an unfortunate side effect for these improvements. Why "unfortunate?"
Because many users have never run an intrusion prevention system before and may not be prepared for the level of effort required to run an intrusion prevention system.

Here is my personal thoughts about running Intrusion Prevention in Untangle:
* There will be false positives, often thousands of them. You can ignore them or disable the rules you don't want to hear about. This is the nature of IPS.
* Intrusion Prevention plays just a small role within Untangle and within most organizations overall security landscape.
* Keeping a Intrusion Prevention system running can be a lot of work.
* The amount of security gained from Intrusion Prevention is debatable.
* Given, the above points in most networks it may make sense to NOT enable Intrusion Prevention as the gain is minimal but the effort is real. If you aren't prepared to deal with Intrusion Prevention I would suggest you NOT run Intrusion Prevention.

Hopefully this will help explain some of the things people are seeing in 9.0
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com

Last edited by dmorris; 06-27-2011 at 07:15 PM..
dmorris is offline  
Old 06-27-2011, 12:00 PM   #2 (permalink)
Master Untangler
 
Join Date: Apr 2007
URLs submitted: 1
Posts: 608
bigdessert is an unknown quantity at this point
Default

to me this is great news!
bigdessert is offline  
Old 06-27-2011, 05:59 PM   #3 (permalink)
Master Untangler
 
f1assistance's Avatar
 
Join Date: Apr 2009
Location: Holly Springs, NC
URLs submitted: 154
Posts: 218
f1assistance is on a distinguished road
Default

I second that!
Whining about what I should have deployed in this environment seems way more costly...plus, we've all been there, done that!
Besides, HOPE is not a security strategy.
f1assistance is offline  
Old 06-27-2011, 06:11 PM   #4 (permalink)
Master Untangler
 
adrianp918's Avatar
 
Join Date: May 2009
Posts: 397
adrianp918 is on a distinguished road
Send a message via AIM to adrianp918 Send a message via MSN to adrianp918 Send a message via Yahoo to adrianp918 Send a message via Skype™ to adrianp918
Default

is there a list of what the corresponding codes mean...for novice people?
adrianp918 is offline  
Old 06-27-2011, 06:16 PM   #5 (permalink)
Master Untangler
 
adrianp918's Avatar
 
Join Date: May 2009
Posts: 397
adrianp918 is on a distinguished road
Send a message via AIM to adrianp918 Send a message via MSN to adrianp918 Send a message via Yahoo to adrianp918 Send a message via Skype™ to adrianp918
Default

never mind i found it i believe in the logs and description its self
adrianp918 is offline  
Old 06-27-2011, 06:32 PM   #6 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,457
sky-knight is on a distinguished road
Default

So the official position is that this thing is now as annoying as a block by default firewall?

I need to upgrade.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 06-27-2011, 06:36 PM   #7 (permalink)
Master Untangler
 
Join Date: Jan 2009
Posts: 721
fasttech is on a distinguished road
Default

Quote:
Originally Posted by sky-knight View Post
So the official position is that this thing is now as annoying as a block by default firewall?
Or, perhaps it's something along the lines of, 'Now, it actually works.'.
fasttech is offline  
Old 06-27-2011, 08:22 PM   #8 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,457
sky-knight is on a distinguished road
Default

True, that module has always been really quiet. I'm going to have to disable it in my field units until I can get a feel for the updated functionality.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 06-27-2011, 09:19 PM   #9 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,612
dmorris is on a distinguished road
Default

Maybe I'm the only one not looking forward to the flood of calls and posts saying "OMG I've been ATTACKED!!!11"
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 06-27-2011, 10:11 PM   #10 (permalink)
Master Untangler
 
Join Date: Jan 2009
Posts: 721
fasttech is on a distinguished road
Default

Let's just say, out of many, varied installations over the years, this is the only ips system that I didn't have to tune. Look forward to the change.
fasttech is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:22 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2