Hi,
i'm a student currently researching and PoC'ing the viability of an IPS for a company.
Currently i'm working on a Proof of Concept in a test environment at the company.
For the PoC i'm running SELKS in a docker container on OracleLinux (not ideal but the company needs it to run on OL).
Bringing up the project with docker-compose all works fine, everything is alright according to portainer.
Because the test environment is behind the company firewall, which denies traffic unless allowed, I can't use http to get the rules. To get around this I downloaded them and manually uploaded them to scirius.
Apart from that, I also create a single rule file with "Alert icmp any any -> $HOME_NET any (msg: "IMCP traffic detected"; sid:1; )" to test alerting.
My problem is, I'm not getting any alerts, not from pinging nor from replaying pcap's.
Does anyone have any idea what could be going wrong?
I understand that this is missing quite a lot of information and I would be happy to supply anything that might help with troubleshooting.
Kind regards,
Joppe