Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rule Signature ID (SID) causing issues with Windows updates.

    Scheduled Pinned Locked Moved IDS/IPS
    12 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee @JonathanLee
      last edited by

      @jonathanlee

      Gental-Giant. (n.d.). Windows 10, version 1909, connection endpoints for non-enterprise editions - windows privacy. Windows Privacy | Microsoft Docs. Retrieved January 14, 2022, from https://docs.microsoft.com/en-us/windows/privacy/windows-endpoints-1909-non-enterprise-editions

      Reference from Microsoft Docs for approved Windows URLS

      Make sure to upvote

      JonathanLeeJ 1 Reply Last reply Reply Quote 0
      • JonathanLeeJ
        JonathanLee @JonathanLee
        last edited by

        @jonathanlee

        When I search under active rules I can not find it, does anyone know its location? Or know a work around? My Passlists use to work up until a couple days ago.

        Make sure to upvote

        1 Reply Last reply Reply Quote 0
        • bmeeksB
          bmeeks
          last edited by bmeeks

          Two things.

          First, you should really be looking on the ALERTS tab when tracking down what rule or rules are firing. On that tab you will see the GID:SID for every rule that fired an alert. Alerts equal blocks when using legacy mode (unless the IP is on an active Pass List).

          Second, the rule you have highlighted is an HTTP_INSPECT preprocessor rule. That means it is part of the built-in rules Snort uses to look for protocol anomalies. You will need to find the SID for the particular HTTP_INSPECT rule that fired. You can find that on the ALERTS tab. Sort the list there by IP and you should be able to find the triggered rule. Once you find it, there is an icon for disabling that rule, or adding it to a suppress list to suppress by source or destination IP. Hover your mouse over the icons on the ALERTS tab and a pop-up tooltip will appear describing what each icon does.

          Last item I will mention is that when using IP lists for CDNs (content delivery networks), you are always likely to run into a situation where the CDN uses a new IP address that is not yet on the list you are downloading and using for your alias. That may be why your Pass List entry suddenly quit working.

          JonathanLeeJ 3 Replies Last reply Reply Quote 1
          • JonathanLeeJ
            JonathanLee @bmeeks
            last edited by

            @bmeeks

            Yes I also set the DNS resolve to faster speed that fixed the time out issue.

            I found the location thanks

            sid.JPG

            Make sure to upvote

            1 Reply Last reply Reply Quote 0
            • JonathanLeeJ
              JonathanLee @bmeeks
              last edited by JonathanLee

              @bmeeks

              Thanks for the reply again.

              I am still having a issue with the use of http downloads they do not connect on the linux apt-get update or on Windows. They are removed from the blocked list however they never show traffic. I have port 80 closed and all traffic is forced into the proxy, however the updates do not work, everything else works however. I did set up and have wpad working I can see it run on the proxy sometimes also under real time. But the system for http downloads for updates does not work. I can however download the update files directly they come in as windows cabinet files when I click the link, but they will not make it to my system from the proxy.

              Make sure to upvote

              1 Reply Last reply Reply Quote 0
              • JonathanLeeJ
                JonathanLee @bmeeks
                last edited by

                @bmeeks Screen Shot 2022-01-14 at 6.04.37 PM.png

                This is what happens the system shows checking for updates non stop it and if you look at the Squid Realtime it only shows 0 with a weird http.

                Make sure to upvote

                JonathanLeeJ 1 Reply Last reply Reply Quote 0
                • JonathanLeeJ
                  JonathanLee @JonathanLee
                  last edited by

                  @jonathanlee I even made a NAT from port 80 to 3128 to see if that fixed it nothing, if I click the link that shows 0 it will download from Chrome however so that is working. Weird ?

                  Make sure to upvote

                  JonathanLeeJ 1 Reply Last reply Reply Quote 0
                  • JonathanLeeJ
                    JonathanLee @JonathanLee
                    last edited by

                    @jonathanlee

                    WPAD works and tests ok

                    wpaddownloads.JPG

                    Make sure to upvote

                    JonathanLeeJ 1 Reply Last reply Reply Quote 0
                    • JonathanLeeJ
                      JonathanLee @JonathanLee
                      last edited by

                      @jonathanlee

                      cab.JPG

                      I can download the HTTP file from Chrome .cab

                      Make sure to upvote

                      JonathanLeeJ 1 Reply Last reply Reply Quote 0
                      • JonathanLeeJ
                        JonathanLee @JonathanLee
                        last edited by JonathanLee

                        @jonathanlee
                        tcp0.JPG

                        Packet capture shows tcp 0 and never connects however for the direct download from Windows update.

                        Make sure to upvote

                        JonathanLeeJ 1 Reply Last reply Reply Quote 0
                        • JonathanLeeJ
                          JonathanLee @JonathanLee
                          last edited by

                          @jonathanlee

                          cabfile.JPG

                          Once cab file is open it has a text file inside.

                          What can cause this type of issue ?

                          Make sure to upvote

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.