Re: Snort drops the incoming HTTP response packets
"Al Lewis \(allewi\) via Snort-users" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <BL3PR11MB57158F38CA2A1607DE8D14F6DA729@BL3PR11MB5715.namprd11.prod.outlook.com> |
At first glance it looks like you need to simplify things a bit and only run one instance of snort inline to narrow things down. Do you have a copy of the traffic unimpeded? This would help rule out any network related problems you have. Couple of things to try.... Add the --daq dump to your startup command in order to get a pcap file name "inline-out.pcap". This will show at want point it stops passing traffic (if that is the case). Disable all rules / inspections. Do you still have the same problem? Is this problem seen with other types of traffic or is it HTTP specific? Albert Lewis ENGINEER.SOFTWARE ENGINEERING SOURCEfire, Inc. now part of Cisco Email: [email protected]<mailto:[email protected]> ________________________________ From: Tamás Németh <[email protected]> Sent: Thursday, August 25, 2022 4:42 AM To: [email protected] <[email protected]> Cc: Al Lewis (allewi) <[email protected]> Subject: Re: [Snort-users] Snort drops the incoming HTTP response packets Thank you very much for your efforts! I uploaded all the information you might need (and a little more) to https://drive.google.com/file/d/14Wu-zLI_L8BZxpArEC5EYAgLfeo46X0a/view?usp=sharing It's a ZIP file, which I will delete in a few days. After decompressing, please start with reading README.txt. Thank you in advance for your help, Tamás Németh IT sysadmin Waterworks of Sopron, Hungary Al Lewis (allewi) <[email protected]<mailto:[email protected]>> ezt írta (időpont: 2022. aug. 24., Sze, 22:44): Hello, Can you share the configuration you are using? Do you have a pcap of the traffic in question? Albert Lewis ENGINEER.SOFTWARE ENGINEERING SOURCEfire, Inc. now part of Cisco Email: [email protected]<mailto:[email protected]> ________________________________ From: Snort-users <[email protected]<mailto:[email protected]>> on behalf of Tamás Németh via Snort-users <[email protected]<mailto:[email protected]>> Sent: Wednesday, August 24, 2022 11:13 AM To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>> Subject: [Snort-users] Snort drops the incoming HTTP response packets Dear All! I face the problem that snort drops the incoming HTTP response packets from a certain unencrypted HTTP website, but it does not log the dropping event in /var/log/snort/alert , so I have no idea, which rule is responsible (if a rule does in anyway). I'm using the registered rules snortrules-snapshot-29200.tar.gz , and the website is http://mekh.hu How could I figure out the reason of snort to drop these packets. Thank you in advance, Tamás Németh IT sysadmin Waterworks of Sopron, Hungary _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette