Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

I want IPS to work on certain subnets rather than interface binded. #8122

Open
gobiursus opened this issue Dec 10, 2024 · 2 comments
Open

I want IPS to work on certain subnets rather than interface binded. #8122

gobiursus opened this issue Dec 10, 2024 · 2 comments
Labels
support Community support

Comments

@gobiursus
Copy link

Important notices

Before you add a new report, we ask you kindly to acknowledge the following:

Is your feature request related to a problem? Please describe.
I want to let IPS system only work with the traffic on certain subnets behind a interface and I don't want to create extra Vlan interface
A clear and concise description of what the problem is including your motivation for the request,
i.e. "For the purpose of [...] I am missing a solution that will [...]."

Describe the solution you like
In IPS setting panel, I would be allowed to input whatever source or destination subnet/addresses that I want IPS to work on instead of interface based.

@Monviech
Copy link
Member

Couldn't this solve your issue?

https://docs.opnsense.org/manual/how-tos/ips-bypass.html

You still select the interface but you can bypass any net you do not want to inspect.

@Monviech Monviech added the support Community support label Dec 11, 2024
@gobiursus
Copy link
Author

Couldn't this solve your issue?

https://docs.opnsense.org/manual/how-tos/ips-bypass.html

You still select the interface but you can bypass any net you do not want to inspect.

I want those subnets run as IDS mode and rest of subnets run under IPS mode.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
support Community support
Development

No branches or pull requests

2 participants