Re: snort3: reject rule problem

Meridoff via Snort-devel <[email protected]> Tue, 1 Oct 2019 19:04:27 +0300
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <CAFfuDwxyf0CHQiDuUQOVS_8MxMCOuuN015=Qb0b+dX+uTv21+g@mail.gmail.com>
--===============5609091644493967412==
Content-Type: multipart/alternative; boundary="0000000000007205970593db822d"

--0000000000007205970593db822d
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

>> That is per design =E2=80=93 the alert kicks off the active responses.  =
The
alert is logged, but the responses are not.

I have many pings so it must be many alerts, but it's only one alert for
pings, when active response is ON.
Is it normanl ?

=D0=B2=D1=82, 1 =D0=BE=D0=BA=D1=82. 2019 =D0=B3. =D0=B2 17:42, Meridoff <oa=
[email protected]>:

> I have many pings so it must be many alerts, but it's only one, when
> active response is ON.
> Is it normanl ?
>
> =D1=87=D1=82, 26 =D1=81=D0=B5=D0=BD=D1=82. 2019 =D0=B3. =D0=B2 17:41, Rus=
s Combs (rucombs) <[email protected]>:
>
>> That is per design =E2=80=93 the alert kicks off the active responses.  =
The alert
>> is logged, but the responses are not.
>>
>>
>>
>> *From: *Meridoff <[email protected]>
>> *Date: *Thursday, September 26, 2019 at 10:25 AM
>> *To: *"Russ Combs (rucombs)" <[email protected]>
>> *Subject: *Re: [Snort-devel] snort3: reject rule problem
>>
>>
>>
>> Thanks, it's became better - Host/Port Unreachable sent for each ping
>> packet now.
>>
>>
>>
>> BUT in log goes only 1st ping packet. For other ping packets - no alerts
>> in log..
>>
>>
>>
>> I use active.min_interval =3D 1
>>
>> So this settings fix problem with Active response pacekts, but in log
>> only 1st alert for all cases..
>>
>>
>>
>> =D1=87=D1=82, 26 =D1=81=D0=B5=D0=BD=D1=82. 2019 =D0=B3. =D0=B2 14:36, Ru=
ss Combs (rucombs) <[email protected]>:
>>
>> Take a look at the active module.  Try configuring active.min_interval.
>>
>>
>>
>> Russ
>>
>>
>>
>> *From: *Snort-devel <[email protected]> on behalf of
>> Meridoff via Snort-devel <[email protected]>
>> *Reply-To: *Meridoff <[email protected]>
>> *Date: *Wednesday, September 25, 2019 at 5:39 PM
>> *To: *"[email protected]" <[email protected]>
>> *Subject: *[Snort-devel] snort3: reject rule problem
>>
>>
>>
>> Hello
>>
>> I have reject rule that send Port unreachable for ping.
>>
>>
>>
>> It's Ok, but only for 1st packet.
>>
>>
>>
>> The next ping packets are silently dropped and not detected and not logg=
ed.
>>
>>
>>
>> reject icmp 192.168.0.1 any -> any any ( gid:8000; sid:1; msg:"ping";  )
>>
>>
>>
>> This happens when stream and stream_icmp inspectors are in config.
>>
>>
>>
>> If I remove stream {} and/or stream_icmp {} inspectors from snort lua co=
nfig, then ALL OK: each packet is
>>
>> dropped, logged and ICMP Port unreach is sending on each dropped packet.
>>
>>
>>
>>
>>
>> Part of config:
>>
>>
>>
>> stream=3D{}
>>
>> stream_icmp=3D{}
>>
>> reject=3D{control=3D"port"}
>>
>>
>>
>> Thanks.
>>
>>

--0000000000007205970593db822d
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr"><div>&g=
t;&gt; That is per design =E2=80=93 the alert kicks off the active response=
s.=C2=A0 The alert is logged, but the responses are not.<br><br></div><div>=
I have many pings so it must be many alerts, but it&#39;s only one alert fo=
r pings, when active response is ON.=C2=A0</div><div>Is it normanl ?</div><=
/div></div></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" clas=
s=3D"gmail_attr">=D0=B2=D1=82, 1 =D0=BE=D0=BA=D1=82. 2019 =D0=B3. =D0=B2 17=
:42, Meridoff &lt;<a href=3D"mailto:[email protected]">[email protected]</a=
>&gt;:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0=
px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=
=3D"ltr"><div>I have many pings so it must be many alerts, but it&#39;s onl=
y one, when active response is ON.=C2=A0</div><div>Is it normanl ?</div><br=
><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">=D1=87=D1=
=82, 26 =D1=81=D0=B5=D0=BD=D1=82. 2019 =D0=B3. =D0=B2 17:41, Russ Combs (ru=
combs) &lt;<a href=3D"mailto:[email protected]" target=3D"_blank">rucombs@c=
isco.com</a>&gt;:<br></div><blockquote class=3D"gmail_quote" style=3D"margi=
n:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex=
">





<div lang=3D"EN-US">
<div>
<p class=3D"MsoNormal">That is per design =E2=80=93 the alert kicks off the=
 active responses.=C2=A0 The alert is logged, but the responses are not.<u>=
</u><u></u></p>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div style=3D"border-right:none;border-bottom:none;border-left:none;border-=
top:1pt solid rgb(181,196,223);padding:3pt 0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:12pt;color:black">From: =
</span></b><span style=3D"font-size:12pt;color:black">Meridoff &lt;<a href=
=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>&gt;<b=
r>
<b>Date: </b>Thursday, September 26, 2019 at 10:25 AM<br>
<b>To: </b>&quot;Russ Combs (rucombs)&quot; &lt;<a href=3D"mailto:rucombs@c=
isco.com" target=3D"_blank">[email protected]</a>&gt;<br>
<b>Subject: </b>Re: [Snort-devel] snort3: reject rule problem<u></u><u></u>=
</span></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Thanks, it&#39;s became better - Host/Port Unreachab=
le sent for each ping packet now.=C2=A0
<u></u><u></u></p>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">BUT in log goes only 1st ping packet. For other ping=
 packets - no alerts in log..<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">I use active.min_interval =3D 1<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">So this settings fix problem with Active response=C2=
=A0pacekts, but in log only 1st alert for all cases..<u></u><u></u></p>
</div>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<div>
<p class=3D"MsoNormal">=D1=87=D1=82, 26 =D1=81=D0=B5=D0=BD=D1=82. 2019 =D0=
=B3. =D0=B2 14:36, Russ Combs (rucombs) &lt;<a href=3D"mailto:rucombs@cisco=
.com" target=3D"_blank">[email protected]</a>&gt;:<u></u><u></u></p>
</div>
<blockquote style=3D"border-top:none;border-right:none;border-bottom:none;b=
order-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4=
.8pt;margin-right:0in">
<div>
<div>
<p class=3D"MsoNormal">Take a look at the active module.=C2=A0 Try configur=
ing active.min_interval.<u></u><u></u></p>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<p class=3D"MsoNormal">Russ<u></u><u></u></p>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<div style=3D"border-right:none;border-bottom:none;border-left:none;border-=
top:1pt solid rgb(181,196,223);padding:3pt 0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:12pt;color:black">From:
</span></b><span style=3D"font-size:12pt;color:black">Snort-devel &lt;<a hr=
ef=3D"mailto:[email protected]" target=3D"_blank">snort-d=
[email protected]</a>&gt; on behalf of Meridoff via Snort-devel =
&lt;<a href=3D"mailto:[email protected]" target=3D"_blank">snort-=
[email protected]</a>&gt;<br>
<b>Reply-To: </b>Meridoff &lt;<a href=3D"mailto:[email protected]" target=
=3D"_blank">[email protected]</a>&gt;<br>
<b>Date: </b>Wednesday, September 25, 2019 at 5:39 PM<br>
<b>To: </b>&quot;<a href=3D"mailto:[email protected]" target=3D"_=
blank">[email protected]</a>&quot; &lt;<a href=3D"mailto:snort-de=
[email protected]" target=3D"_blank">[email protected]</a>&gt;<=
br>
<b>Subject: </b>[Snort-devel] snort3: reject rule problem</span><u></u><u><=
/u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<div>
<div>
<div>
<pre><span style=3D"color:black">Hello</span><u></u><u></u></pre>
<pre><span style=3D"color:black">I have reject rule that send Port unreacha=
ble for ping.</span><u></u><u></u></pre>
<pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre>
<pre><span style=3D"color:black">It&#39;s Ok, but only for 1st packet.</spa=
n><u></u><u></u></pre>
<pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre>
<pre><span style=3D"color:black">The next ping packets are silently dropped=
 and not detected and not logged.</span><u></u><u></u></pre>
<pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre>
<pre><span style=3D"color:black">reject icmp 192.168.0.1 any -&gt; any any =
( gid:8000; sid:1; msg:&quot;ping&quot;;=C2=A0 )</span><u></u><u></u></pre>
<pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre>
<pre><span style=3D"color:black">This happens when stream and stream_icmp i=
nspectors are in config.</span><u></u><u></u></pre>
<pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre>
<pre><span style=3D"color:black">If I remove stream {} and/or stream_icmp {=
} inspectors from snort lua config, then ALL OK: each packet is</span><u></=
u><u></u></pre>
<pre><span style=3D"color:black">dropped, logged and ICMP Port unreach is s=
ending on each dropped packet.</span><u></u><u></u></pre>
<pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre>
<pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre>
<pre><span style=3D"color:black">Part of config:</span><u></u><u></u></pre>
<pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre>
<pre><span style=3D"color:black">stream=3D{}</span><u></u><u></u></pre>
<pre><span style=3D"color:black">stream_icmp=3D{}</span><u></u><u></u></pre=
>
<pre><span style=3D"color:black">reject=3D{control=3D&quot;port&quot;}</spa=
n><u></u><u></u></pre>
<pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre>
<pre><span style=3D"color:black">Thanks.</span><u></u><u></u></pre>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</div>
</div>
</div>

</blockquote></div></div>
</blockquote></div>

--0000000000007205970593db822d--

--===============5609091644493967412==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!

--===============5609091644493967412==--