Re: Log flooded with "(decode) same src/dst IP"

"Al Lewis \(allewi\) via Snort-users" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <BL3PR11MB5715D4F3F894EF70FE091C30DA049@BL3PR11MB5715.namprd11.prod.outlook.com>
Have you tried commenting out this line "--enable_builtin_rules = true,"? Its under the IPS section of the config file..

"    -- use this to enable decoder and inspector alerts
    --enable_builtin_rules = true,
"


Albert Lewis

ENGINEER.SOFTWARE ENGINEERING

SOURCEfire, Inc. now part of Cisco

Email: [email protected]<mailto:[email protected]>

________________________________
From: Snort-users <[email protected]> on behalf of Amish via Snort-users <[email protected]>
Sent: Tuesday, November 15, 2022 2:31 AM
To: [email protected] <[email protected]>
Subject: [Snort-users] Log flooded with "(decode) same src/dst IP"

Hello

Recently I upgraded from snort 2 to 3.

I am using snort 3.1.45 in NFQUEUE (IPS) mode.

The snort is installed on gateway and monitors all traffic to and fro LAN.

I use snort-community rules, installed via pulled pork 3.

I also use latest OpenAppID.

I noticed that the log file (alert_fast) gets flooded with following lines:

11/15-12:38:25.616624 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586
11/15-12:38:25.618817 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586
11/15-12:38:25.620745 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586
11/15-12:38:25.622575 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586
11/15-12:38:25.623990 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586
11/15-12:38:25.625335 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586

This occurs because 192.168.1.151 connects to its own public IP which
gets redirected back to 192.168.1.151 via NAT.

So how do I disable this rule? Grepping for "same src" in snort.rules
file gives nothing.

So I have no clue where the rule is located. It filled up 200GB of
harddisk in less than 15 days.

Can someone give pointers?

Thank you,

Amish.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        [email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.