Rulesets
The I(DP)S rulesets are a group of rules that you can enable to detect certain types of traffic – for example, a signature that's been designed to prevent attacks on web servers. In OPNsense, it is possible to enable different rulesets simultaneously. By default, the available rulesets are as follows:
Abuse.ch
: These are rulesets that are provided by theAbuse.ch
project. They focus on blacklists based on an IP address's reputation.- Proofpoint's Emerging Threat Open (ET Open): This is the community version of the Proofpoint ruleset. It's more limited than the ET Pro version.
- OPNsense Application Detection: This is OPNsense's project ruleset. It contains rules for controlling web applications such as YouTube, Netflix, Dropbox, and others.
Whatever ruleset you decide to use, you must download and install these rulesets before enabling them.
Some additional rulesets that are available as plugins are as follows:
-
...