LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 09-14-2009, 05:11 AM   #1
EricTRA
Guru
 
Registered: May 2009
Location: Barcelona, Spain
Distribution: LMDE + Linux 3.2.0-1.dmz.6-amd64, RHEL5+6, Mulltiple testing
Posts: 6,193
Blog Entries: 1

Rep: Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149
How to exclude local traffic on Snort/acidbase


Hi all,

Last week I put our Squid servers in our datacenter and everything is working great. So I'm starting to monitor the incoming traffic and encounter also the traffic from the second squid server. I have the two squid servers set up in a high availability setup using heartbeat. The packages sent by this process are detected and captured by Snort as
Code:
#0-(2-247475) 	 [local] [snort] ICMP PING speedera
(listed like this in acidbase,
and in the alert log as
Code:
[**] [1:480:5] ICMP PING speedera [**]
[Classification: Misc activity] [Priority: 3] 
09/14-11:08:40.066654 192.168.253.11 -> 192.168.253.10
ICMP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:92 DF
Type:8  Code:0  ID:2799   Seq:1  ECHO
I don't want to disable ICMP entirely but am very new at this. How do I tell Snort to ignore this particular traffic since it's generating a lot of alerts? I'm reading up on Snort and such but would like to disable this specific one since it's eating up space at a very speedy rate.

Any help is greatly appreciated.

Kind regards,

Eric
 
Old 09-15-2009, 06:43 PM   #2
shizzles
LQ Newbie
 
Registered: Jun 2005
Location: Chicago
Distribution: Ubuntu 10.10 & CentOS
Posts: 21

Rep: Reputation: 1
Quote:
Originally Posted by EricTRA View Post

Code:
#0-(2-247475) 	 [local] [snort] ICMP PING speedera
(listed like this in acidbase,
and in the alert log as
Code:
[**] [1:480:5] ICMP PING speedera [**]
[Classification: Misc activity] [Priority: 3] 
09/14-11:08:40.066654 192.168.253.11 -> 192.168.253.10
ICMP TTL:64 TOS:0x0 ID:0 IpLen:20 DgmLen:92 DF
Type:8  Code:0  ID:2799   Seq:1  ECHO


there should be a file called threshold.conf in /etc/snort/ This is were signature can be suppressed either by signature ID, destination IP or source IP.

Edit that to say something like,

suppress gen_id #, sig_id #, track by_src, ip 192.168.253.11

The gen_id and sig_id # are usually in the signature or by clicking on the [snort] link on the acidbase.

Also check to make sure that the variables in snort.conf are set properly specifically the $HOME_NET and $EXTERNAL_NET

Last edited by shizzles; 09-15-2009 at 06:46 PM.
 
Old 09-16-2009, 01:04 AM   #3
EricTRA
Guru
 
Registered: May 2009
Location: Barcelona, Spain
Distribution: LMDE + Linux 3.2.0-1.dmz.6-amd64, RHEL5+6, Mulltiple testing
Posts: 6,193
Blog Entries: 1

Original Poster
Rep: Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149Reputation: 1149
Hi shizzles,

Thank you very much for your reply. Just configured it and works like a charm.

Kind regards,

Eric
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Snort/Base reporting no traffic, Ntop not showing any TCP traffic. a2brute Linux - Security 1 08-10-2009 01:21 PM
populating SNORT/ACIDLAB/ACIDBASE database with ulogd eentonig Linux - Software 3 08-31-2008 06:26 AM
installing snort on high traffic gateway bog it down? kcorupe Linux - Server 2 04-06-2007 09:02 AM
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 03:59 PM
ICMP traffic in Snort+BASE perfect_circle Linux - Security 2 04-16-2005 07:16 PM


All times are GMT -5. The time now is 02:39 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration