SSL Blacklist, Feodotracker

Hi @trish,

sorry for replying late. :slight_smile:

I am not sure some of them are checked and some not

Those are defaults provided by the IPS ruleset maintainer - usually, rules disabled by default cause false positives or other collateral damage in certain environments, and unless you have a special need, it is usually wise to let them turned off.

How could I add them to the IPFire ?

By simply enabling the corresponding rule sections. Please refer to the documentation for further details.

As mentioned here, the missing JA3 support is a bug and currently prevents the usage of some IDS rulesets, particularly some provided by abuse.ch.

I see a lot of the Rulesets for EThreats are not checked.

See above.

Thanks, and best regards,
Peter Müller

1 Like