Hi @trish,
sorry for replying late.
I am not sure some of them are checked and some not
Those are defaults provided by the IPS ruleset maintainer - usually, rules disabled by default cause false positives or other collateral damage in certain environments, and unless you have a special need, it is usually wise to let them turned off.
How could I add them to the IPFire ?
By simply enabling the corresponding rule sections. Please refer to the documentation for further details.
As mentioned here, the missing JA3 support is a bug and currently prevents the usage of some IDS rulesets, particularly some provided by abuse.ch.
I see a lot of the Rulesets for EThreats are not checked.
See above.
Thanks, and best regards,
Peter Müller