mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-19 07:23:03 +02:00
ids-functions.pl: Tune rules to always monitor in both directions.
This will allow to scan the traffic from an EXTERNAL_NET to the HOME_NET and from the HOME_NET to the EXTERNAL_NET. Reference: 10273 Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
This commit is contained in:
@@ -742,6 +742,9 @@ sub write_modify_sids_file($) {
|
||||
# Write file header.
|
||||
print FILE "#Autogenerated file. Any custom changes will be overwritten!\n";
|
||||
|
||||
# Tune rules to monitor in both directions.
|
||||
print FILE "modifysid \* \"\-\>\" \| \"\<\>\"\n";
|
||||
|
||||
# Check if the traffic only should be monitored.
|
||||
unless($ruleaction eq "alert") {
|
||||
# Tell oinkmaster to switch all rules from alert to drop.
|
||||
|
||||
Reference in New Issue
Block a user