Problems with snort inline
Corey Minyard <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
I'm having trouble getting snort working in inline mode. I have the latest released versions of snort (2.9.18.1) and libdaq (2.0.7) installed with no rules running in inline mode with afpacket, basically a stock install with no rules, standard snort.conf. This is in qemu with user mode networking. The first few packets go though fine, but after that the packets go through, but they don't seem to work. I haven't figured out why they aren't working, but the other end doesn't seem to respond to them. Pings work fine, so packets are getting through. I tried turning off normalization, but that didn't help. For instance, if I ssh in, I can see the packet come in, and the packet go out, and then the packets going out get retransmitted until the connection times out. The FIN packet seems to go through, though (not 100% sure). When I first bring snort up a few packets go both ways, like I can read a small web page or the ssh connection does the key exchange. But after that it doesn't work. I guess I should add info on the network setup. I have eth0 in qemu on a user network, then I create a veth pair and run snort between one veth and eth0. Then I bring up networking on the other veth. dhcp works fine, at least the first one. If I just bring up eth0 directly, it works fine. I tried a tun device (bridge) for qemu, and it seems to work better, I can reliably fetch small web pages, but ssh still doesn't work. I'm sure I'm doing something stupid, but I can't figure it out. -corey _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette