ADR-0006:49:
The unconfigured Snort package is removed rather than left installed.
There is no evidence this happened, and
docs/runbooks/enable-suricata.md:30
still lists removing it as a prerequisite — which suggests it is still
there.
Small, but worth closing out properly:
- Two IDS packages installed on the same firewall is a configuration that
invites someone to enable the wrong one at 1am.
- An unconfigured package still receives updates and still has attack surface,
on the device that terminates every VLAN.
- The ADR asserts it as done. Either it is, and the runbook prerequisite should
go; or it is not, and the ADR is describing an intention as a fact.
Needs one look at the pfSense package list to resolve, and then an edit to
whichever of the two documents turns out to be wrong.
ADR-0006:49:
There is no evidence this happened, and
docs/runbooks/enable-suricata.md:30still lists removing it as a prerequisite — which suggests it is still
there.
Small, but worth closing out properly:
invites someone to enable the wrong one at 1am.
on the device that terminates every VLAN.
go; or it is not, and the ADR is describing an intention as a fact.
Needs one look at the pfSense package list to resolve, and then an edit to
whichever of the two documents turns out to be wrong.