Re: Log flooded with "(decode) same src/dst IP"
"Al Lewis \(allewi\) via Snort-users" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <BL3PR11MB5715D4F3F894EF70FE091C30DA049@BL3PR11MB5715.namprd11.prod.outlook.com> |
Have you tried commenting out this line "--enable_builtin_rules = true,"? Its under the IPS section of the config file..
" -- use this to enable decoder and inspector alerts
--enable_builtin_rules = true,
"
Albert Lewis
ENGINEER.SOFTWARE ENGINEERING
SOURCEfire, Inc. now part of Cisco
Email: [email protected]<mailto:[email protected]>
________________________________
From: Snort-users <[email protected]> on behalf of Amish via Snort-users <[email protected]>
Sent: Tuesday, November 15, 2022 2:31 AM
To: [email protected] <[email protected]>
Subject: [Snort-users] Log flooded with "(decode) same src/dst IP"
Hello
Recently I upgraded from snort 2 to 3.
I am using snort 3.1.45 in NFQUEUE (IPS) mode.
The snort is installed on gateway and monitors all traffic to and fro LAN.
I use snort-community rules, installed via pulled pork 3.
I also use latest OpenAppID.
I noticed that the log file (alert_fast) gets flooded with following lines:
11/15-12:38:25.616624 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586
11/15-12:38:25.618817 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586
11/15-12:38:25.620745 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586
11/15-12:38:25.622575 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586
11/15-12:38:25.623990 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586
11/15-12:38:25.625335 [**] [116:151:1] "(decode) same src/dst IP" [**]
[Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 ->
192.168.1.151:58586
This occurs because 192.168.1.151 connects to its own public IP which
gets redirected back to 192.168.1.151 via NAT.
So how do I disable this rule? Grepping for "same src" in snort.rules
file gives nothing.
So I have no clue where the rule is located. It filled up 200GB of
harddisk in less than 15 days.
Can someone give pointers?
Thank you,
Amish.
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette