Re: snort3: reject rule problem
Meridoff via Snort-devel <[email protected]> Tue, 1 Oct 2019 19:04:27 +0300
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <CAFfuDwxyf0CHQiDuUQOVS_8MxMCOuuN015=Qb0b+dX+uTv21+g@mail.gmail.com> |
--===============5609091644493967412== Content-Type: multipart/alternative; boundary="0000000000007205970593db822d" --0000000000007205970593db822d Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable >> That is per design =E2=80=93 the alert kicks off the active responses. = The alert is logged, but the responses are not. I have many pings so it must be many alerts, but it's only one alert for pings, when active response is ON. Is it normanl ? =D0=B2=D1=82, 1 =D0=BE=D0=BA=D1=82. 2019 =D0=B3. =D0=B2 17:42, Meridoff <oa= [email protected]>: > I have many pings so it must be many alerts, but it's only one, when > active response is ON. > Is it normanl ? > > =D1=87=D1=82, 26 =D1=81=D0=B5=D0=BD=D1=82. 2019 =D0=B3. =D0=B2 17:41, Rus= s Combs (rucombs) <[email protected]>: > >> That is per design =E2=80=93 the alert kicks off the active responses. = The alert >> is logged, but the responses are not. >> >> >> >> *From: *Meridoff <[email protected]> >> *Date: *Thursday, September 26, 2019 at 10:25 AM >> *To: *"Russ Combs (rucombs)" <[email protected]> >> *Subject: *Re: [Snort-devel] snort3: reject rule problem >> >> >> >> Thanks, it's became better - Host/Port Unreachable sent for each ping >> packet now. >> >> >> >> BUT in log goes only 1st ping packet. For other ping packets - no alerts >> in log.. >> >> >> >> I use active.min_interval =3D 1 >> >> So this settings fix problem with Active response pacekts, but in log >> only 1st alert for all cases.. >> >> >> >> =D1=87=D1=82, 26 =D1=81=D0=B5=D0=BD=D1=82. 2019 =D0=B3. =D0=B2 14:36, Ru= ss Combs (rucombs) <[email protected]>: >> >> Take a look at the active module. Try configuring active.min_interval. >> >> >> >> Russ >> >> >> >> *From: *Snort-devel <[email protected]> on behalf of >> Meridoff via Snort-devel <[email protected]> >> *Reply-To: *Meridoff <[email protected]> >> *Date: *Wednesday, September 25, 2019 at 5:39 PM >> *To: *"[email protected]" <[email protected]> >> *Subject: *[Snort-devel] snort3: reject rule problem >> >> >> >> Hello >> >> I have reject rule that send Port unreachable for ping. >> >> >> >> It's Ok, but only for 1st packet. >> >> >> >> The next ping packets are silently dropped and not detected and not logg= ed. >> >> >> >> reject icmp 192.168.0.1 any -> any any ( gid:8000; sid:1; msg:"ping"; ) >> >> >> >> This happens when stream and stream_icmp inspectors are in config. >> >> >> >> If I remove stream {} and/or stream_icmp {} inspectors from snort lua co= nfig, then ALL OK: each packet is >> >> dropped, logged and ICMP Port unreach is sending on each dropped packet. >> >> >> >> >> >> Part of config: >> >> >> >> stream=3D{} >> >> stream_icmp=3D{} >> >> reject=3D{control=3D"port"} >> >> >> >> Thanks. >> >> --0000000000007205970593db822d Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr"><div>&g= t;> That is per design =E2=80=93 the alert kicks off the active response= s.=C2=A0 The alert is logged, but the responses are not.<br><br></div><div>= I have many pings so it must be many alerts, but it's only one alert fo= r pings, when active response is ON.=C2=A0</div><div>Is it normanl ?</div><= /div></div></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" clas= s=3D"gmail_attr">=D0=B2=D1=82, 1 =D0=BE=D0=BA=D1=82. 2019 =D0=B3. =D0=B2 17= :42, Meridoff <<a href=3D"mailto:[email protected]">[email protected]</a= >>:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0= px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir= =3D"ltr"><div>I have many pings so it must be many alerts, but it's onl= y one, when active response is ON.=C2=A0</div><div>Is it normanl ?</div><br= ><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">=D1=87=D1= =82, 26 =D1=81=D0=B5=D0=BD=D1=82. 2019 =D0=B3. =D0=B2 17:41, Russ Combs (ru= combs) <<a href=3D"mailto:[email protected]" target=3D"_blank">rucombs@c= isco.com</a>>:<br></div><blockquote class=3D"gmail_quote" style=3D"margi= n:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex= "> <div lang=3D"EN-US"> <div> <p class=3D"MsoNormal">That is per design =E2=80=93 the alert kicks off the= active responses.=C2=A0 The alert is logged, but the responses are not.<u>= </u><u></u></p> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> <div style=3D"border-right:none;border-bottom:none;border-left:none;border-= top:1pt solid rgb(181,196,223);padding:3pt 0in 0in"> <p class=3D"MsoNormal"><b><span style=3D"font-size:12pt;color:black">From: = </span></b><span style=3D"font-size:12pt;color:black">Meridoff <<a href= =3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>><b= r> <b>Date: </b>Thursday, September 26, 2019 at 10:25 AM<br> <b>To: </b>"Russ Combs (rucombs)" <<a href=3D"mailto:rucombs@c= isco.com" target=3D"_blank">[email protected]</a>><br> <b>Subject: </b>Re: [Snort-devel] snort3: reject rule problem<u></u><u></u>= </span></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">Thanks, it's became better - Host/Port Unreachab= le sent for each ping packet now.=C2=A0 <u></u><u></u></p> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">BUT in log goes only 1st ping packet. For other ping= packets - no alerts in log..<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">I use active.min_interval =3D 1<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal">So this settings fix problem with Active response=C2= =A0pacekts, but in log only 1st alert for all cases..<u></u><u></u></p> </div> </div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> <div> <div> <p class=3D"MsoNormal">=D1=87=D1=82, 26 =D1=81=D0=B5=D0=BD=D1=82. 2019 =D0= =B3. =D0=B2 14:36, Russ Combs (rucombs) <<a href=3D"mailto:rucombs@cisco= .com" target=3D"_blank">[email protected]</a>>:<u></u><u></u></p> </div> <blockquote style=3D"border-top:none;border-right:none;border-bottom:none;b= order-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4= .8pt;margin-right:0in"> <div> <div> <p class=3D"MsoNormal">Take a look at the active module.=C2=A0 Try configur= ing active.min_interval.<u></u><u></u></p> <p class=3D"MsoNormal">=C2=A0<u></u><u></u></p> <p class=3D"MsoNormal">Russ<u></u><u></u></p> <p class=3D"MsoNormal">=C2=A0<u></u><u></u></p> <div style=3D"border-right:none;border-bottom:none;border-left:none;border-= top:1pt solid rgb(181,196,223);padding:3pt 0in 0in"> <p class=3D"MsoNormal"><b><span style=3D"font-size:12pt;color:black">From: </span></b><span style=3D"font-size:12pt;color:black">Snort-devel <<a hr= ef=3D"mailto:[email protected]" target=3D"_blank">snort-d= [email protected]</a>> on behalf of Meridoff via Snort-devel = <<a href=3D"mailto:[email protected]" target=3D"_blank">snort-= [email protected]</a>><br> <b>Reply-To: </b>Meridoff <<a href=3D"mailto:[email protected]" target= =3D"_blank">[email protected]</a>><br> <b>Date: </b>Wednesday, September 25, 2019 at 5:39 PM<br> <b>To: </b>"<a href=3D"mailto:[email protected]" target=3D"_= blank">[email protected]</a>" <<a href=3D"mailto:snort-de= [email protected]" target=3D"_blank">[email protected]</a>><= br> <b>Subject: </b>[Snort-devel] snort3: reject rule problem</span><u></u><u><= /u></p> </div> <div> <p class=3D"MsoNormal">=C2=A0<u></u><u></u></p> </div> <div> <div> <div> <div> <pre><span style=3D"color:black">Hello</span><u></u><u></u></pre> <pre><span style=3D"color:black">I have reject rule that send Port unreacha= ble for ping.</span><u></u><u></u></pre> <pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre> <pre><span style=3D"color:black">It's Ok, but only for 1st packet.</spa= n><u></u><u></u></pre> <pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre> <pre><span style=3D"color:black">The next ping packets are silently dropped= and not detected and not logged.</span><u></u><u></u></pre> <pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre> <pre><span style=3D"color:black">reject icmp 192.168.0.1 any -> any any = ( gid:8000; sid:1; msg:"ping";=C2=A0 )</span><u></u><u></u></pre> <pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre> <pre><span style=3D"color:black">This happens when stream and stream_icmp i= nspectors are in config.</span><u></u><u></u></pre> <pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre> <pre><span style=3D"color:black">If I remove stream {} and/or stream_icmp {= } inspectors from snort lua config, then ALL OK: each packet is</span><u></= u><u></u></pre> <pre><span style=3D"color:black">dropped, logged and ICMP Port unreach is s= ending on each dropped packet.</span><u></u><u></u></pre> <pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre> <pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre> <pre><span style=3D"color:black">Part of config:</span><u></u><u></u></pre> <pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre> <pre><span style=3D"color:black">stream=3D{}</span><u></u><u></u></pre> <pre><span style=3D"color:black">stream_icmp=3D{}</span><u></u><u></u></pre= > <pre><span style=3D"color:black">reject=3D{control=3D"port"}</spa= n><u></u><u></u></pre> <pre><span style=3D"color:black">=C2=A0</span><u></u><u></u></pre> <pre><span style=3D"color:black">Thanks.</span><u></u><u></u></pre> </div> </div> </div> </div> </div> </div> </blockquote> </div> </div> </div> </blockquote></div></div> </blockquote></div> --0000000000007205970593db822d-- --===============5609091644493967412== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-devel mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-devel Please visit http://blog.snort.org for the latest news about Snort! --===============5609091644493967412==--