Security and filtering packages
Optional security packages extend FreeSense with certificate automation, reputation feeds, behavioral decisions, intrusion detection and prevention, and—on Development—web proxy policy. Install only the control that has a defined owner, data source, false-positive process, and recovery path.
| Package | Purpose | Primary operating concern |
|---|---|---|
| ACME Certificates | Certificate enrollment and renewal | Account and DNS-validation credentials; consumer deployment |
| CrowdSec | Behavioral security decisions | Managed firewall table and false-positive response |
| DNS and IP Blocklists | Reputation-based DNS and IP filtering | Feed scope, update health, and exceptions |
| Suricata IDS/IPS | Detection and inline prevention | Capacity, rule tuning, pass lists, and blocking rollout |
| Secure Web Gateway | Explicit/transparent web policy | Development-only; TLS inspection and identity policy |
| Web Gateway Local Antivirus | Local ICAP malware scanning | Development-only; CPU, storage, and response handling |
Safety baseline
Section titled “Safety baseline”Start security controls in observation mode wherever possible. Record the approved feed or rule sources, update interval, notification owner, retention limit, and emergency-disable procedure. Do not combine several intensive inspection packages until the appliance has demonstrated sustained CPU, memory, storage, and packet-processing headroom.
Read Suricata IDS/IPS and CrowdSec before enabling blocking. The Secure Web Gateway guide is available only in 1.1 Development.