Boost Your pfSense Security With CrowdSec's New Plugin

Поделиться
HTML-код
  • Опубликовано: 13 дек 2024

Комментарии • 67

  • @Isaac-d2w5c
    @Isaac-d2w5c 4 месяца назад +25

    Thought this was CrowdStrike for a good minute.

  • @DavidDavisL
    @DavidDavisL 4 месяца назад +7

    Happy to see this. In the interest of making the install as clean and simple as possible, I will watch for the package to arrive in the "Available" list, then take a look. I'm sure Tom will be covering this as well.

  • @ronaldvargo4113
    @ronaldvargo4113 4 месяца назад +3

    Thanks but I would have like to have seen where do the CropwdSec rules end up? Are they like PFblocker and it a Wan rule with a large list of aliases? Also would have like to seen from the UI the options in the settings for it.

  • @davidb_thetruth
    @davidb_thetruth 4 месяца назад +6

    Great video Jay, one quick question, does CrowdSec work well with other apps on Pfsense i.e. pfBlockerNG?

  • @walterstarks7865
    @walterstarks7865 4 месяца назад +2

    Since Netgate recommends uninstalling 3rd party plugins prior to updating Pfsense and the most recent Pfsense update borked the crowdsec plugin for early users I’m wondering if anyone has a link to the uninstall how-to? It also seems that the plugin must be uninstalled prior to updating it as well to prevent crashing Pfsense.

  • @bluecup25
    @bluecup25 4 месяца назад +38

    CrowdS... (Vietnam flashbacks)

  • @odnankenobi
    @odnankenobi 4 месяца назад +6

    I knew this video easy coming yet my brain still read "crowdS-" and I laughed nervously until reading ir right on the third try

  • @philippef.4590
    @philippef.4590 4 месяца назад +1

    Thank you

  • @CedroCron
    @CedroCron 4 месяца назад

    Jay you might want to blur your Netgate ID on your PfSense Plus install.

  • @ivlis32
    @ivlis32 4 месяца назад

    Can explain how it exactly detects penetration or attacks on the network? On a Linux server it scans SSH or http logs, but what does it scan on a firewall, firewalls don't usually have open ports to the internet.

  • @finnleytra3555
    @finnleytra3555 4 месяца назад

    Anyone have issues with crowdsec detecting the remediation component (9:44)? I have confirmed the firewall bouncer is running with system ctl, but the remediation component is showing a 0. Love the content btw!!!

    • @finnleytra3555
      @finnleytra3555 4 месяца назад +1

      Jumped the gun, took about 20 minutes to update

  • @samgaw1
    @samgaw1 4 месяца назад +2

    I followed all the commands to the letter, when I try to run the cscli caps register command I get the error cscli: Command not found. Anyone know where I may have gone wrong?

    • @SlimTom
      @SlimTom 3 месяца назад

      me to. did you find the solution?

    • @stp952
      @stp952 3 месяца назад

      @@SlimTom use sudo ?

    • @umohibomette4850
      @umohibomette4850 3 месяца назад

      I'm running pfSense Plus 24.03 as the admin and have the same error. How did you resolve? Thanks

    • @samgaw1
      @samgaw1 3 месяца назад

      The solution was to run the commands from within the web console. Anything with cscli run from there and it will work.

    • @umohibomette4850
      @umohibomette4850 3 месяца назад

      @@samgaw1 I'm good now. It may have been a timing issue. 🙂

  • @JonitoFischer
    @JonitoFischer 4 месяца назад

    The crowdstrike plugin comes with a all zeroes payload

  • @sadonomic
    @sadonomic 4 месяца назад

    Is there any advantage to installing this if you're not hosting or making your network available to non-local devices?

    • @crowdsec
      @crowdsec 4 месяца назад +2

      For the Security Engine not so much since that component parse logs and takes actions, even if you dont expose stuff we can still detect port scanning but since there nothing open they wont be able to find anything anyways.

    • @sadonomic
      @sadonomic 4 месяца назад

      Suspected as much, will give it a try if I open things up. Thanks for the reply!

  • @adamzbucki237
    @adamzbucki237 4 месяца назад

    Question, basically we need to reinstall the binaries on pfsense to update the version correct?

    • @crowdsec
      @crowdsec 4 месяца назад +4

      Yes currently you would need to run the `pkg add -f` command again but only for the pfSense-pkg-crowdsec-.pkg. Until we get added to the main packages on pfSense which we hope is soon!

  • @HtetMyatHtun-v6n
    @HtetMyatHtun-v6n 4 месяца назад

    Thanks. But in my case, cscli command not found error when register the capi.

    • @AV-th6kn
      @AV-th6kn Месяц назад

      Same, cscli: Command not found. Running 2.7.2, not 24.03 as Jay.

    • @AV-th6kn
      @AV-th6kn Месяц назад

      WARN can't load CAPI credentials from '/usr/local/etc/crowdsec/online_api_credentials.yaml' (missing login field)
      FATA the Central API (CAPI) must be configured with 'cscli capi register'
      # cscli capi register
      this solved the issue, and then i was able to # cscli console enroll -e context

  • @NFvidoJagg2
    @NFvidoJagg2 2 месяца назад

    I suspect this wont work very well if your behind a NATed ISP modem. all the traffic would look like it's coming from the gateway.

  • @awwtergirl7040
    @awwtergirl7040 4 месяца назад +1

    Crowd...oh Sec. Close one.

  • @Grehund
    @Grehund 4 месяца назад

    Your "pfSense Plugin Documentation" link doesn't take me to the documentation.

  • @propeto13
    @propeto13 Месяц назад

    can you shed some light on how to update it?

  • @GpconnectInfohotspot
    @GpconnectInfohotspot 4 месяца назад +7

    we need to stop making our devices talking to i don't know which people server over the internet ! crowdsec services look great and useful but why can we not host the console ourself on our own server and just being able to retrieve the databases for know vulnerability from their servers ? is there any live scan going on ?

    • @bzmrgonz
      @bzmrgonz 4 месяца назад +2

      I agree with you completely, it should be local-first. This is the biggest take-away from crowstrike outtage, everyone is praising intune for storing the bitlocker keys etc.. but they forget that, the giant baskets of user/company information is what bad actors relentlessly attack... for that very reason. So Crowdsec should allow us local-first, even if they make telemetrics mandatory or whatever. All bad actors target centralized systems, and this strong-arm push to cloud makes no sense.

    • @nadtz
      @nadtz 4 месяца назад +2

      While personally I would prefer something local in practice I can understand why they wen't with the centralized console after using Crowdsec for however long I've been using it on opnsense. There are some dynamic aspects of how it work that maybe could be implemented in a local only install but in the end you would still need to be constantly connecting to their servers for updates anyway. If you want something local only there are other options like Suricata but you will need to have a much greater understanding of what you are doing to get that configured beyond the default rules.

    • @StephenMcGregor1986
      @StephenMcGregor1986 4 месяца назад

      The recent CrowdStrike thing taught me to throw all of my justifications for cloud and remote anything straight into the bin

    • @crowdsec
      @crowdsec 4 месяца назад +1

      The console is purely optional, if you dont want to use it and only want to use the "Plugins" page on pfsense go ahead! The only downside is you cant get access to the additional blocklists (For being apart of the network you get the CrowdSec community blocklist which doesnt need a console account)

  • @micturatedupon
    @micturatedupon 4 месяца назад +1

    Mainly watch you on The Homelab Show; not sure if it's the different background, or the hair, but you look a solid five years younger! Give either stylist a raise!

  • @freeitclasseswindows9115
    @freeitclasseswindows9115 4 месяца назад

    hellow anyone can help me about pfsense. my web server accessing from out side after port forwarding.but not accessible from local network.plz help

  • @michaelsims7728
    @michaelsims7728 4 месяца назад +1

    How many thought he was talking about CrowdStrike LOL ...

  • @kukla-mukla6000
    @kukla-mukla6000 4 месяца назад

    good timing lol

  • @kilosierraalpha
    @kilosierraalpha 4 месяца назад +7

    I pass on anything with "crowd" in its name.

  • @bzmrgonz
    @bzmrgonz 4 месяца назад +1

    FINALLY.. it's here.. I was thissss close to switching to opnsense.. just for this plugin. Was beginning to feel like a stepchild on pfsense.

  • @tockar
    @tockar 3 месяца назад

    It's funny because it is still unavailable.

    • @LearnLinuxTV
      @LearnLinuxTV  3 месяца назад

      I know, it's super frustrating. Behind the camera me and several other people are very frustrated with this. If it gets worse, there might be another video coming.

  • @PlatyBZH
    @PlatyBZH 4 месяца назад +1

    Why the F are there so many scam bots in early video comments ? It's really anoying

    • @LearnLinuxTV
      @LearnLinuxTV  4 месяца назад

      It's a cat and mouse game between script kiddies and RUclips. Sorry about all of that

  • @sammieollie
    @sammieollie 3 месяца назад +1

    I don't know if I trust this.

  • @RazoBeckett.
    @RazoBeckett. 4 месяца назад +3

    Crowdsec >>> CrowdStrike ...

  • @esra_erimez
    @esra_erimez 4 месяца назад

    You have some strange bots in the comment section.

    • @LearnLinuxTV
      @LearnLinuxTV  4 месяца назад

      Given the capabilities of my audience, I'm surprised it doesn't happen more often. Annoying, I agree.

  • @GaryGarcia-n6c
    @GaryGarcia-n6c 3 месяца назад

    Johnson Steven Hernandez Joseph Miller Sandra

  • @stenlypurba
    @stenlypurba 4 месяца назад

    I am sorry. I don't believe you're excited like you said in 00:35 by the look on your facial expression.

  • @KayeBarnett-b4y
    @KayeBarnett-b4y 3 месяца назад

    Thomas Helen Miller Anthony Lopez Sharon

  • @ChristopherJackson-t1r
    @ChristopherJackson-t1r 2 месяца назад

    Lopez David Taylor Anna Miller Christopher

  • @esra_erimez
    @esra_erimez 4 месяца назад

    Isn't CrowdSec expensive?

    • @LearnLinuxTV
      @LearnLinuxTV  4 месяца назад +1

      It's free

    • @esra_erimez
      @esra_erimez 4 месяца назад +1

      @@LearnLinuxTV Interesting, I have to tell my I.T. dept about this. We are already using pfSense as one of the firewall layers.

    • @jacksoncremean1664
      @jacksoncremean1664 4 месяца назад

      @@esra_erimez I think your confusing CrowdStrike with CrowdSec.

  • @louisfifteen
    @louisfifteen 4 месяца назад

    I guess it is only relevant for business owners. I'm just a private user without servers or anything, just a regular linux user, private.