<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>Opendium Documentation  - Recent changes [en-gb]</title>
		<link>https://docs.opendium.com/wiki/Special:RecentChanges</link>
		<description>Track the most recent changes to the wiki in this feed.</description>
		<language>en-GB</language>
		<generator>MediaWiki 1.38.4</generator>
		<lastBuildDate>Wed, 26 Aug 2026 23:48:35 GMT</lastBuildDate>
		<item>
			<title>Police Cyber Alarm</title>
			<link>https://docs.opendium.com/w/index.php?title=Police_Cyber_Alarm&amp;diff=525&amp;oldid=523</link>
			<guid isPermaLink="false">https://docs.opendium.com/w/index.php?title=Police_Cyber_Alarm&amp;diff=525&amp;oldid=523</guid>
			<description>&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 15:56, 4 August 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l29&quot;&gt;Line 29:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 29:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= What Could the NPCC Do? =&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= What Could the NPCC Do? =&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This situation demonstrates why maintaining trust is of the utmost importance when it comes to security.  The NPCC, an organisation who should attract the highest levels of trust, responded to security concerns by &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;demonstrating that they could not be trusted to make truthful &lt;/del&gt;public statements regarding the security of their security product.  The security researcher, Paul Moore, has said that he believes that the NPCC have been misled by Pervade Software&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;, and &lt;/del&gt;it may well be &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;true &lt;/del&gt;that the NPCC did not have the technical expertise to properly evaluate the security concerns, and therefore just deferred to Pervade Software, trusting their contractor more than an external whistleblower.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This situation demonstrates why maintaining trust is of the utmost importance when it comes to security.  The NPCC, an organisation who should attract the highest levels of trust, responded to security concerns by &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;making apparently untruthful &lt;/ins&gt;public statements regarding the security of their security product.  The security researcher, Paul Moore, has said that he believes that the NPCC have been misled by Pervade Software&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;; &lt;/ins&gt;it may well be &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;the case &lt;/ins&gt;that the NPCC did not have the technical expertise to properly evaluate the security concerns, and therefore just deferred to Pervade Software, trusting their contractor more than an external whistleblower.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Now that trust in the people responsible for Cyber Alarm has been lost, it will be very hard for them to regain it.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Now that trust in the people responsible for Cyber Alarm has been lost, it will be very hard for them to regain it.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Tue, 04 Aug 2026 14:56:06 GMT</pubDate>
			<dc:creator>Steve</dc:creator>
			<comments>https://docs.opendium.com/wiki/Talk:Police_Cyber_Alarm</comments>
		</item>
		<item>
			<title>Firewall logging</title>
			<link>https://docs.opendium.com/w/index.php?title=Firewall_logging&amp;diff=524&amp;oldid=522</link>
			<guid isPermaLink="false">https://docs.opendium.com/w/index.php?title=Firewall_logging&amp;diff=524&amp;oldid=522</guid>
			<description>&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:39, 3 August 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l72&quot;&gt;Line 72:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 72:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Replace &amp;quot;192.0.2.1&amp;quot; with the IP address of the target syslog server.  Also see the [https://docs.rsyslog.com/doc/configuration/modules/omfwd.html Rsyslog documentation] for more options.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Replace &amp;quot;192.0.2.1&amp;quot; with the IP address of the target syslog server.  Also see the [https://docs.rsyslog.com/doc/configuration/modules/omfwd.html Rsyslog documentation] for more options.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Restart both the rsyslog and firewall services.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Knowledgebase]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Knowledgebase]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 03 Aug 2026 16:39:50 GMT</pubDate>
			<dc:creator>Steve</dc:creator>
			<comments>https://docs.opendium.com/wiki/Talk:Firewall_logging</comments>
		</item>
		<item>
			<title>Police Cyber Alarm</title>
			<link>https://docs.opendium.com/w/index.php?title=Police_Cyber_Alarm&amp;diff=523&amp;oldid=521</link>
			<guid isPermaLink="false">https://docs.opendium.com/w/index.php?title=Police_Cyber_Alarm&amp;diff=523&amp;oldid=521</guid>
			<description>&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:29, 3 August 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l22&quot;&gt;Line 22:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 22:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It is important to understand that we (Opendium) have not audited the Cyber Alarm software ourselves.  However, we do have enough technical knowledge to understand and be extremely concerned regarding the evidence that has been published by Paul Moore.  There has been no transparency regarding the audit carried out by Bytes, and the way that both the NPCC, and Pervade Software have behaved doesn't lead to us having any confidence that the product is safe and secure to run on a customer's network.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;It is important to understand that we (Opendium) have not audited the Cyber Alarm software ourselves.  However, we do have enough technical knowledge to understand and be extremely concerned regarding the evidence that has been published by Paul Moore.  There has been no transparency regarding the audit carried out by Bytes, and the way that both the NPCC, and Pervade Software have behaved doesn't lead to us having any confidence that the product is safe and secure to run on a customer's network.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;= Status =&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Opendium UTM doesn't currently support linking with Cyber Alarm and the police have not published an API specification to firewall vendors.  Our understanding is that the necessary work to send firewall events to Cyber Alarm would be fairly straight forward and we are happy to do so if any customers want this functionality, although since a formal specification had not been published the communications may well not be in a format that Cyber Alarm can understand.&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;As it stands, we have not developed this functionality, as each time we have been asked about this and explained our concerns, customers have suddenly lost interest in installing the Cyber Alarm product on their network.&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;At the very least, if a school decides to run this product, they should ensure that it is only connected to a completely isolated network, not to their main LAN.&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Requirements for Schools =&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Requirements for Schools =&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l46&quot;&gt;Line 46:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 39:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Publish an official playbook for how they will to respond to vulnerability reports, including a commitment not to engage in legal threats in response to the publication of bug reports.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Publish an official playbook for how they will to respond to vulnerability reports, including a commitment not to engage in legal threats in response to the publication of bug reports.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Create a &amp;quot;Bug Bounty&amp;quot; programme, to reward security researchers who discover vulnerabilities in the software.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Create a &amp;quot;Bug Bounty&amp;quot; programme, to reward security researchers who discover vulnerabilities in the software.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;= Status =&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Opendium UTM can be linked with Cyber Alarm.  If you require this, please ask our engineers to configure it.  There is further technical information available on the [[Firewall logging]] page.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Given the security concerns, if a school decides to run this product, at the very least they should ensure that it is only connected to a completely isolated network, not to their main LAN.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Vendor Contact Log ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Vendor Contact Log ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 03 Aug 2026 16:29:51 GMT</pubDate>
			<dc:creator>Steve</dc:creator>
			<comments>https://docs.opendium.com/wiki/Talk:Police_Cyber_Alarm</comments>
		</item>
		<item>
			<title>Firewall logging</title>
			<link>https://docs.opendium.com/w/index.php?title=Firewall_logging&amp;diff=522&amp;oldid=0</link>
			<guid isPermaLink="false">https://docs.opendium.com/w/index.php?title=Firewall_logging&amp;diff=522&amp;oldid=0</guid>
			<description>&lt;p&gt;Created page with &amp;quot;Upon a customer&amp;#039;s request, Opendium engineers can configure the firewall component to send logs to a syslog server on the local network.  The firewall is stateful and each log line reflects the establishment of a new flow.  The format of the data sent to a remote syslog server is (subject to change):   &amp;lt;nowiki&amp;gt;&amp;lt;Date&amp;gt; &amp;lt;Host name&amp;gt; firewall&amp;lt;PID&amp;gt;: &amp;lt;Flow ID&amp;gt; &amp;lt;Zone crossing&amp;gt; &amp;lt;User&amp;gt; &amp;lt;User ident source&amp;gt; &amp;lt;Decision&amp;gt; (&amp;lt;Decider&amp;gt;) &amp;lt;Flow source&amp;gt; &amp;lt;Flow destination&amp;gt; &amp;lt;Layer 4 protocol&amp;gt; &amp;lt;...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Upon a customer's request, Opendium engineers can configure the firewall component to send logs to a syslog server on the local network.&lt;br /&gt;
&lt;br /&gt;
The firewall is stateful and each log line reflects the establishment of a new flow.  The format of the data sent to a remote syslog server is (subject to change):&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&amp;lt;Date&amp;gt; &amp;lt;Host name&amp;gt; firewall&amp;lt;PID&amp;gt;: &amp;lt;Flow ID&amp;gt; &amp;lt;Zone crossing&amp;gt; &amp;lt;User&amp;gt; &amp;lt;User ident source&amp;gt; &amp;lt;Decision&amp;gt; (&amp;lt;Decider&amp;gt;) &amp;lt;Flow source&amp;gt; &amp;lt;Flow destination&amp;gt; &amp;lt;Layer 4 protocol&amp;gt; &amp;lt;Layer 7 protocol&amp;gt; &amp;lt;Packets&amp;gt;/&amp;lt;Octets&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The parameters are:&lt;br /&gt;
&lt;br /&gt;
* '''&amp;lt;Date&amp;gt;''' - The date and time that the event was logged.&lt;br /&gt;
* '''&amp;lt;Host name&amp;gt;''' - The host name of the Opendium system (quite possibly, but not always &amp;quot;opendium&amp;quot;).&lt;br /&gt;
* '''&amp;lt;PID&amp;gt;''' - The process ID of the firewall.&lt;br /&gt;
* '''&amp;lt;Flow ID&amp;gt;''' - Each flow is assigned a numeric ID when it is first logged.&lt;br /&gt;
* '''&amp;lt;Zone crossing&amp;gt;''' - This is one of the following values to indicate which firewall zones the connection is crossing between:&lt;br /&gt;
** '''Local_In''' - The flow was initiated by a device on the internet, destined for the Opendium system itself.&lt;br /&gt;
** '''Local_Out''' - The flow was initiated by the Opendium system itself.  Note: this is not usually logged.&lt;br /&gt;
** '''Ingress''' - The flow was initiated by a device on the internet, destined for an internal network.&lt;br /&gt;
** '''Egress''' - The flow was initiated by a device on an internal network, destined for the internet.&lt;br /&gt;
** '''Internal''' - The flow is between devices located on different internal firewall zones.&lt;br /&gt;
** '''External''' - The flow is between devices located on different external (internet) firewall zones.  Note: Opendium systems do not usually have multiple external zones configured, so this would not usually be seen.&lt;br /&gt;
** '''-''' - Internal error.  This should never be seen.&lt;br /&gt;
** Note that traffic between devices on the same zone is not restricted or logged.  Depending on the network configuration, this traffic may not even pass through the firewall.&lt;br /&gt;
* '''&amp;lt;User&amp;gt;''' - The user name associated with this traffic flow, if known.  May include an &amp;quot;@&amp;lt;Realm&amp;gt;&amp;quot; suffix.  If no user is known, this will be &amp;quot;-&amp;quot;.&lt;br /&gt;
* '''&amp;lt;User ident source&amp;gt;''' - Where the user identification information came from.  e.g. &amp;quot;RADIUS&amp;quot;, &amp;quot;Proxy: Kerberos&amp;quot;, etc.  Note that the firewall does not receive user identification from the client for each connection, and the user is inferred from other information, such as RADIUS accounting data, recently authenticated web proxy connections, etc.&lt;br /&gt;
* '''&amp;lt;Decision&amp;gt;''' - The decision that the firewall has reached regarding this flow.  This may be prefixed by &amp;quot;INFO/&amp;quot; (see below) and is one of:&lt;br /&gt;
** '''UNDECIDED''' - The flow is temporarily allowed, but a decision has not yet been made.  If the firewall needs to perform deep packet inspection in order to make a decision, it must temporarily allow the flow in order to gather traffic to inspect.  A second &amp;quot;INFO/&amp;quot; line will be logged once an outcome has been reached (see below).&lt;br /&gt;
** '''SHORT''' - A previously UNDECIDED flow has ended before a decision had been made.  In terms of which traffic has been let through the firewall, this is equivalent to ALLOW, but the traffic may not match any allowed firewall bundles.  See the notes on the &amp;quot;INFO/&amp;quot; prefix, below.&lt;br /&gt;
** '''UNKNOWN''' - The start of the flow has been missed and there is therefore very limited information available.  This is most likely caused by a restart of the firewall&lt;br /&gt;
** '''DENY''' - Traffic associated with the flow is being dropped.  Flows which are not allowed and originate on the internet usually result in DENY if possible, but deep packet inspection decisions may necessitate a REJECT instead.&lt;br /&gt;
** '''REJECT''' - Traffic associated with the flow is being rejected with suitable ICMP error responses.  Flows which are not allowed and originate from local networks usually result in REJECT.&lt;br /&gt;
** '''INTERCEPT''' - Traffic has been redirected to a service running on the Opendium system.  This is often web traffic which is being redirected to the transparent proxy and web filter, but may also be some other supported protocols such as DNS and NTP.&lt;br /&gt;
** '''ALLOW''' - Traffic associated with the flow is being allowed to pass through the system.&lt;br /&gt;
** '''INTERNAL_ERROR''' - Internal error.  This should never be seen.&lt;br /&gt;
* '''&amp;lt;Decider&amp;gt;''' - Which part of the firewall made the decision:&lt;br /&gt;
** '''kernel''' - The decision was made by rules set up within the operating system kernel.&lt;br /&gt;
** '''user''' - The decision was made by the userspace process.&lt;br /&gt;
** This may also include the suffix &amp;quot;''' - destination banned'''&amp;quot;.  When deep packet inspection is used to control traffic, the firewall must allow the connection to be temporarily allowed whilst it gathers and inspects the traffic.  If the resulting decision is to block the flow, the destination receives a temporary ban.  This ensures that future connections are REJECTed / DROPped outright instead of being allowed initially.&lt;br /&gt;
* '''&amp;lt;Flow source&amp;gt;''' - This is the IP address the device which initiated the flow, surrounded by square brackets.  If the flow's layer 4 protocol has port numbers, the closing square bracket is followed by a colon and the source port.  e.g.&lt;br /&gt;
** '''[192.0.2.1]:123'''&lt;br /&gt;
** '''[2001:db8::1]:123'''&lt;br /&gt;
* '''&amp;lt;Flow destination&amp;gt;''' - The destination of the flow.  This is in the same format as &amp;lt;Flow source&amp;gt; above.&lt;br /&gt;
* '''&amp;lt;Layer 4 protocol&amp;gt;''' - Identifies the layer 4 protocol, such as &amp;quot;tcp&amp;quot;, &amp;quot;udp&amp;quot;, &amp;quot;sctp&amp;quot;, etc.  If a textual name is not known, the numeric protocol identifier is used.&lt;br /&gt;
* '''&amp;lt;Layer 7 protocol&amp;gt;''' - The layer 7 protocol which deep packet inspection has identified.  This will be either a single protocol name, or a pair of names separated by a forward slash.  Additionally the following special values are used:&lt;br /&gt;
** '''-''' - Deep packet inspection is not being performed on this flow.&lt;br /&gt;
** '''[Unknown]''' - Deep packet inspection was not able to identify the protocol being used.&lt;br /&gt;
** '''[In progress]''' - Deep packet inspection has not yet determined what protocol is being used.  A second &amp;quot;INFO/&amp;quot; line will be logged once deep packet inspection has concluded (see below).&lt;br /&gt;
* '''&amp;lt;Packets&amp;gt;''' - How many packets associated with this flow had been seen at the time it was logged.&lt;br /&gt;
* '''&amp;lt;Octets&amp;gt;''' - How many octets associated with this flow had been seen at the time it was logged.&lt;br /&gt;
&lt;br /&gt;
The firewall logs each flow as soon as it receives the first packet.  However, deep packet inspection may not be able to identify the protocol being used until some time later.  Additionally, if a firewalling decision relies on deep packet inspection, it too may need to be deferred until later.  In these cases, a second log entry is recorded for the flow, and it will have its decision prefixed with &amp;quot;INFO/&amp;quot;.  The &amp;quot;INFO/&amp;quot; log can be linked to the original log through the numeric flow ID.  Note that the flow ID is NOT unique, and a &amp;quot;INFO/&amp;quot; log should only be linked with the most recent previous entry with a matching flow ID.&lt;br /&gt;
&lt;br /&gt;
Examples:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;Aug  3 15:56:52 opendium firewall[2106397]: 2342398 Ingress - [None] ALLOW (kernel) [2001:db8:1::45f2] [2001:db8:2::6b51] ipv6-icmp ICMPV6 1/144&lt;br /&gt;
Aug  3 15:56:52 opendium firewall[2106397]: 2342399 Egress - [None] INTERCEPT (kernel) [192.0.2.1]:59564 [198.51.100.23]:443 tcp [In progress] 1/60&lt;br /&gt;
Aug  3 15:56:52 opendium firewall[2106397]: 2342399 Egress - [None] INFO/INTERCEPT (kernel) [192.0.2.1]:59564 [198.51.100.23]:443 tcp SSL 6/2293&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Notes for Opendium engineers ==&lt;br /&gt;
Enable syslog output from the firewall by adding a key to its config table:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;INSERT INTO webfront_firewall.config (key, value) VALUES ('global.syslog', 1);&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Create a file called /etc/rsyslogd.d/10-firewall.conf containing:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;if $programname == 'firewall' then {&lt;br /&gt;
        action(&lt;br /&gt;
                type=&amp;quot;omfwd&amp;quot;&lt;br /&gt;
                target=&amp;quot;192.0.2.1&amp;quot;&lt;br /&gt;
                port=&amp;quot;514&amp;quot;&lt;br /&gt;
                protocol=&amp;quot;udp&amp;quot;&lt;br /&gt;
        )&lt;br /&gt;
        stop&lt;br /&gt;
}&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Replace &amp;quot;192.0.2.1&amp;quot; with the IP address of the target syslog server.  Also see the [https://docs.rsyslog.com/doc/configuration/modules/omfwd.html Rsyslog documentation] for more options.&lt;br /&gt;
&lt;br /&gt;
[[Category:Knowledgebase]]&lt;/div&gt;</description>
			<pubDate>Mon, 03 Aug 2026 16:17:52 GMT</pubDate>
			<dc:creator>Steve</dc:creator>
			<comments>https://docs.opendium.com/wiki/Talk:Firewall_logging</comments>
		</item>
</channel></rss>