Wishlist Request:
Request addition of an “Ignore” option to the “Action” field for Network Control Rules to allow passive logging of Traffic of Interest, and to temporarily disable a specific rule without the need to remove it.
Proposed Option Actions:
With “Ignore” option set for the Action field and “Log as a firewall event if this rule is fired” box checked, the conditions met event is logged, and the firewall goes on to consider the next Network Control Rule.
With “Ignore” option set for the Action field and “Log as a firewall event if this rule is fired” box left Unchecked, the firewall ignores this condition and goes on to consider the next Network Control Rule. This disables the rule, but leaves it in context so it could be re-enabled to Allow/Block this traffic if required.
Discussion:
Effectively monitoring “Traffic of Interest” requires a chronological record of events for tracking down anomalies or scrutinizing traffic from suspicious or untrustworthy sources. This data collection is best performed as it occurs without operator intervention. CIS Firewall (version 5.8.211697.2124) provides such chronological logging when a specific set of conditions (or attributes) pertaining to a packet of data are met, but further requires each packet be “Allowed” or “Blocked” at the time of detection. “Ask” option requires operator intervention in addition to requiring choice to Allow/Block.
If a user wishes to “toggle” a rule on/off they are currently required to remove the rule, then re-enter it. This introduces potential for error since the specific firewall rule conditions checked for and the exact ordering of the rules are critical to the correct operation of the firewall. Temporarily setting an “Ignore” option allows the exact rule to remain in the exact position for later re-enabling if desired.
[attachment deleted by admin]