opnsense / rules

OPNsense IDS/IPS rules
BSD 2-Clause "Simplified" License
73 stars 45 forks source link

Eicar test rules do not work with HTTPS - NOT a real issue #18

Closed rudiservo closed 2 years ago

rudiservo commented 2 years ago

Hi, the eicar test rules are not working on Opnsense version 22.7.4 on a realtek card, IPS mode, promiscuous mode, hyperscan.

Social media rules are working has expected.

The reason is eicar download is over HTTPS on the official site, so you have to intercept HTTPS data.