notebook:ips_ids_information

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
notebook:ips_ids_information [2018/05/17 08:48] – [Initial Release] jliechtynotebook:ips_ids_information [2025/05/12 13:37] (current) – external edit 127.0.0.1
Line 3: Line 3:
 The UniFi Intrusion Prevention System / Intrusion Detection System was released to general availability as a beta feature in the UniFi 5.7.20 stable release, with accompanying USG firmware release 4.4.18. IPS/IDS is supported on on the [[products:unifi:unifi_security_gateway|UniFi Security Gateway]], the [[products:unifi:unifi_security_gateway_pro_4|USG Pro-4]], and the [[products:unifi:unifi_security_gateway_xg_8|USG XG-8]]. The UniFi Intrusion Prevention System / Intrusion Detection System was released to general availability as a beta feature in the UniFi 5.7.20 stable release, with accompanying USG firmware release 4.4.18. IPS/IDS is supported on on the [[products:unifi:unifi_security_gateway|UniFi Security Gateway]], the [[products:unifi:unifi_security_gateway_pro_4|USG Pro-4]], and the [[products:unifi:unifi_security_gateway_xg_8|USG XG-8]].
  
-The UniFi IPS / IDS functionality is based on the [[https://suricata-ids.org/|Suricata Open Source IDS]] version 4.0.4, as of USG firmware release 4.4.22. With this release, only IPv4 traffic is inspected; IPv6 inspection has been noted as being in development.+The UniFi IPS / IDS functionality is based on the [[https://suricata-ids.org/|Suricata Open Source IDS]] version 4.0.4, as of USG firmware release 4.4.22. With this release, only IPv4 traffic is inspected; IPv6 inspection is in development and has been made available in firmware 4.4.24dev.
 ===== Performance ===== ===== Performance =====
 IPS/IDS features disable hardware offload, which reduces performance as described in the Warning on the IPS page of the UniFi Settings. With hardware offload disabled, routing between LAN or VLAN interfaces in a configuration with multiple internal networks is also reduced to the aforementioned stated non-offloaded maximum throughput. IPS/IDS features disable hardware offload, which reduces performance as described in the Warning on the IPS page of the UniFi Settings. With hardware offload disabled, routing between LAN or VLAN interfaces in a configuration with multiple internal networks is also reduced to the aforementioned stated non-offloaded maximum throughput.
  • notebook/ips_ids_information.1526564926.txt.gz
  • Last modified: 2025/05/12 13:37
  • (external edit)