Open Menu
AllLocalCommunitiesFeedsAbout
FBXL Lotide
AllLocalCommunitiesFeedsAbout
Login

OpnSense + Crowdsec = comfort

⁨108⁩ ⁨likes⁩

Submitted ⁨⁨2⁩ ⁨weeks⁩ ago⁩ by ⁨chagall@lemmy.world⁩ to ⁨selfhosted@lemmy.world⁩

https://lemmy.world/pictrs/image/ad2cd523-b290-4918-80ee-90f3e24ea54e.jpeg

original

Comments

Sort:hotnewtop
  • lemmyvore@feddit.nl ⁨2⁩ ⁨weeks⁩ ago

    crowdsec has always struck me as a really odd approach to security. You give out your logs to strangers and block IPs based on their say-so.

    The cause and effect are so far removed that I can’t wrap my head about how it’s supposed to be efficient. It’s been proven in real-world tests that it lags badly behind the first waves of new vulnerabilities and by the time it starts blocking IPs that were related to those attacks the attackers have moved on and there are also patches available.

    The “thousands of IPs blocked” image reminds me of that WWII airplane bullet-holes image.

    original
    • MangoPenguin@lemmy.blahaj.zone ⁨2⁩ ⁨weeks⁩ ago

      I don’t believe there are any logs being transferred, just the abusive IPs are shared with the central DB.

      So if an IP starts hitting a ton of rules (like .env access, repeated 404s, 429s, etc… Or specific AppSec rules) then that IP is blocked and sent to their central DB where it’s pushed out to everyone running Crowdsec.

      original
      • non_burglar@lemmy.world ⁨2⁩ ⁨weeks⁩ ago

        On my setup crowdsec has been more effective than cloudflare at stopping scanners and bots from overloading things

        Cloudflare is in the business of keeping infrastructure up and working. Any security benefits of CF are secondary.

        original
        • -> View More Comments
    • EncryptKeeper@lemmy.world ⁨2⁩ ⁨weeks⁩ ago

      CrowdSec isn’t really for protection against novel threats. It’s just a crowdsourced Fail2Ban that’s extensible with custom rules.

      If you and I are both using CrowdSec, and some foreign machine is trying to brute force into one of my services, then when it tries to do the same to you it doesn’t even get the chance to try. It cuts down on the load.

      You can also define your own scenarios. Most of the rules it ships with block IPs using a leaky bucket method but I have a custom rule that instantly blocks anyone trying to log into anything using usernames like admin, root, pgadmin, etc.

      original
    • chagall@lemmy.world ⁨2⁩ ⁨weeks⁩ ago

      You’re not wrong. If CrowdSec is your entire approach, it’s a little weird. But I use it as a (small) part of my overall blocking strategy. I use other lists and frankly, block most IPs by default. Those other IPs aren’t counted in the email screenshot though… only the CrowdSec based ones are coming through. I think a lot of the 137k above are just scanning bots to be frank.

      original
    • jello@programming.dev ⁨2⁩ ⁨weeks⁩ ago

      Is there an alternative you suggest? I use Crowd-Sec in part because I don’t know of anything else that does the same job. That is, blocks malicious IPs without snooping on all traffic content (looking at you, Cloudflare).

      original
      • lemmyvore@feddit.nl ⁨2⁩ ⁨weeks⁩ ago

        If your services are private they should be behind access authorization or completely private access. Scanning should be a non-issue.

        You can further mitigate scanning by getting wildcard certs, putting A/AAAA records on an obfuscated sub-domain rather than the base domain, and not using wildcard CNAME’s.

        If they services are public you should be using a CDN anyway. If you don’t like the way Cloudflare does things they’re not the only CDN around, but some of the privacy issue is moot when running a public service.

        original
        • -> View More Comments
    • refract@lemmy.zip ⁨2⁩ ⁨weeks⁩ ago

      Do you have a source on the real world tests?

      original
  • afk_strats@lemmy.world ⁨2⁩ ⁨weeks⁩ ago

    That’s really cool. Would you mind posting a few sentences about how you redirected your specific solution and what it’s protecting. That would be super helpful.

    original
  • A_norny_mousse@piefed.zip ⁨2⁩ ⁨weeks⁩ ago

    Tell us more about how crowdsec works (for you)!

    (Didn’t even know it had a web ui)

    original
    • chagall@lemmy.world ⁨2⁩ ⁨weeks⁩ ago

      Sure. So OpnSense is the real gem here. Or really any solid firewall/edge device CrowdSec is an optional (free) add-on module in OpnSense. It’s immediately operational at a minimal level without any registration. However, if you choose to register within the CrowdSec UI then you can load up more lists and tie it to your instance.

      I also load up Hagezi’s Threat Intelligence Blocklists into my OpnSense firewall rules, which get updated (by him) on a rolling 12 hour basis. I also have OpnSense query Github every 12 hours to pull the updates.

      original
    • LeTak@feddit.org ⁨2⁩ ⁨weeks⁩ ago

      It is pretty good I use it on many machines. You install it on your machine with a reverse proxy, it then analyses the traffic logs for malicious activity or for known bad IPs and then creates iptable block rules. The web interface is the cloud interface that it connects to, because as the name implies, it works by using log data from all members to block bad actors efficiently

      original
      • A_norny_mousse@piefed.zip ⁨2⁩ ⁨weeks⁩ ago

        Why with a reverse proxy? I don’t see this mentioned as the default installation method. https://doc.crowdsec.net/u/user_guides/building/

        original
        • -> View More Comments
  • Funwayguy@lemmy.world ⁨2⁩ ⁨weeks⁩ ago

    I have similar setup on my home server except my Crowdsec & Anubis live in a dockerised VPS proxy that tunnels over WireGuard to the real server behind OPNSense. Saves me a ton not having bandwidth obliterating AI crawlers hit my internet bill. As an added bonus, I can move or shutdown the public VPS entry if things get too ‘spicy’ without any downtime on connections via the VPN.

    original