Re: Log flooded with "(decode) same src/dst IP"

Amish via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Thanks that helped indeed. But I wonder if there is detailed help 
instead of one liners.

Also you have mentioned that disabling builtin rules is not recommended 
but then:

1) Why is it disabled by default?
2) Russ Combs mentioned in past that they are just for testing

 > Source: https://seclists.org/snort/2020/q2/69
 > ips.enable_builtin_rules is just a convenience for turning on all 
builtin rules that is primarily used for testing.

I guess I will disable them for now.

Thanks again and Regards,

Amish.

On 15/11/22 13:18, Oleksii Shumeiko -X (oshumeik - SOFTSERVE INC at 
Cisco) wrote:
> Hi.
>
> There are several ways. Consider the following commands:
> ./snort --help-config suppress
> ./snort --help-config ips
> ./snort --help-config enable
>
> So, the first option is to suppress the logging for a given rule 
> and/or IP addresses. For example, adding the following line to your 
> configuration will suppress 116:151 built-in rule:
> suppress = { { gid = 116, sid = 151 } }
>
> The second option is to disable that rule entirely by updating ips states:
> ips.states = ips.states .. [[ alert ( gid:116; sid: 151; enable:no; ) ]]
>
> The third option is to disable all built-in rules (not recommended, 
> but could be useful for debugging purposes):
> ips.enable_builtin_rules = false
>
> Good luck and have a nice day ahead,
> Alexey
>
>
>> On 15 Nov 2022, at 09:31, Amish via Snort-users 
>> <[email protected]> wrote:
>>
>> Hello
>>
>> Recently I upgraded from snort 2 to 3.
>>
>> I am using snort 3.1.45 in NFQUEUE (IPS) mode.
>>
>> The snort is installed on gateway and monitors all traffic to and fro 
>> LAN.
>>
>> I use snort-community rules, installed via pulled pork 3.
>>
>> I also use latest OpenAppID.
>>
>> I noticed that the log file (alert_fast) gets flooded with following 
>> lines:
>>
>> 11/15-12:38:25.616624 [**] [116:151:1] "(decode) same src/dst IP" 
>> [**] [Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
>> 192.168.1.151:58586
>> 11/15-12:38:25.618817 [**] [116:151:1] "(decode) same src/dst IP" 
>> [**] [Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
>> 192.168.1.151:58586
>> 11/15-12:38:25.620745 [**] [116:151:1] "(decode) same src/dst IP" 
>> [**] [Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
>> 192.168.1.151:58586
>> 11/15-12:38:25.622575 [**] [116:151:1] "(decode) same src/dst IP" 
>> [**] [Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
>> 192.168.1.151:58586
>> 11/15-12:38:25.623990 [**] [116:151:1] "(decode) same src/dst IP" 
>> [**] [Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
>> 192.168.1.151:58586
>> 11/15-12:38:25.625335 [**] [116:151:1] "(decode) same src/dst IP" 
>> [**] [Priority: 3] [AppID: SQL Server] {TCP} 192.168.1.151:1433 -> 
>> 192.168.1.151:58586
>>
>> This occurs because 192.168.1.151 connects to its own public IP which 
>> gets redirected back to 192.168.1.151 via NAT.
>>
>> So how do I disable this rule? Grepping for "same src" in snort.rules 
>> file gives nothing.
>>
>> So I have no clue where the rule is located. It filled up 200GB of 
>> harddisk in less than 15 days.
>>
>> Can someone give pointers?
>>
>> Thank you,
>>
>> Amish.
>>
>> _______________________________________________
>> Snort-users mailing list
>> [email protected]
>> Go to this URL to change user options or unsubscribe:
>> https://lists.snort.org/mailman/listinfo/snort-users
>>
>> To unsubscribe, send an email to:
>> [email protected]
>>
>> Please visit http://blog.snort.org to stay current on all the latest 
>> Snort news!
>>
>> Please follow these rules: 
>> https://snort.org/faq/what-is-the-mailing-list-etiquette
>

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.