Log flooded with "(decode) same src/dst IP"

Amish via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Hello

Recently I upgraded from snort 2 to 3.

I am using snort 3.1.45 in NFQUEUE (IPS) mode.

The snort is installed on gateway and monitors all traffic to and fro LAN.

I use snort-community rules, installed via pulled pork 3.

I also use latest OpenAppID.

I noticed that the log file (alert_fast) gets flooded with following lines:

11/15-12:38:25.616624 [**] [116:151:1] "(decode) same src/dst IP" [**] 
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
192.168.1.151:58586
11/15-12:38:25.618817 [**] [116:151:1] "(decode) same src/dst IP" [**] 
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
192.168.1.151:58586
11/15-12:38:25.620745 [**] [116:151:1] "(decode) same src/dst IP" [**] 
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
192.168.1.151:58586
11/15-12:38:25.622575 [**] [116:151:1] "(decode) same src/dst IP" [**] 
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
192.168.1.151:58586
11/15-12:38:25.623990 [**] [116:151:1] "(decode) same src/dst IP" [**] 
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
192.168.1.151:58586
11/15-12:38:25.625335 [**] [116:151:1] "(decode) same src/dst IP" [**] 
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
192.168.1.151:58586

This occurs because 192.168.1.151 connects to its own public IP which 
gets redirected back to 192.168.1.151 via NAT.

So how do I disable this rule? Grepping for "same src" in snort.rules 
file gives nothing.

So I have no clue where the rule is located. It filled up 200GB of 
harddisk in less than 15 days.

Can someone give pointers?

Thank you,

Amish.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.