Re: Snort drops the incoming HTTP response packets
"Al Lewis \(allewi\) via Snort-users" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CH0PR11MB57246A40D396EEC4F2BE8D0EDA739@CH0PR11MB5724.namprd11.prod.outlook.com> |
Hello, Can you share the configuration you are using? Do you have a pcap of the traffic in question? Albert Lewis ENGINEER.SOFTWARE ENGINEERING SOURCEfire, Inc. now part of Cisco Email: [email protected]<mailto:[email protected]> ________________________________ From: Snort-users <[email protected]> on behalf of Tamás Németh via Snort-users <[email protected]> Sent: Wednesday, August 24, 2022 11:13 AM To: [email protected] <[email protected]> Subject: [Snort-users] Snort drops the incoming HTTP response packets Dear All! I face the problem that snort drops the incoming HTTP response packets from a certain unencrypted HTTP website, but it does not log the dropping event in /var/log/snort/alert , so I have no idea, which rule is responsible (if a rule does in anyway). I'm using the registered rules snortrules-snapshot-29200.tar.gz , and the website is http://mekh.hu How could I figure out the reason of snort to drop these packets. Thank you in advance, Tamás Németh IT sysadmin Waterworks of Sopron, Hungary _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette