Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rule Signature ID (SID) causing issues with Windows updates.

    Scheduled Pinned Locked Moved IDS/IPS
    12 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee @JonathanLee
      last edited by

      @jonathanlee

      When I search under active rules I can not find it, does anyone know its location? Or know a work around? My Passlists use to work up until a couple days ago.

      Make sure to upvote

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by bmeeks

        Two things.

        First, you should really be looking on the ALERTS tab when tracking down what rule or rules are firing. On that tab you will see the GID:SID for every rule that fired an alert. Alerts equal blocks when using legacy mode (unless the IP is on an active Pass List).

        Second, the rule you have highlighted is an HTTP_INSPECT preprocessor rule. That means it is part of the built-in rules Snort uses to look for protocol anomalies. You will need to find the SID for the particular HTTP_INSPECT rule that fired. You can find that on the ALERTS tab. Sort the list there by IP and you should be able to find the triggered rule. Once you find it, there is an icon for disabling that rule, or adding it to a suppress list to suppress by source or destination IP. Hover your mouse over the icons on the ALERTS tab and a pop-up tooltip will appear describing what each icon does.

        Last item I will mention is that when using IP lists for CDNs (content delivery networks), you are always likely to run into a situation where the CDN uses a new IP address that is not yet on the list you are downloading and using for your alias. That may be why your Pass List entry suddenly quit working.

        JonathanLeeJ 3 Replies Last reply Reply Quote 1
        • JonathanLeeJ
          JonathanLee @bmeeks
          last edited by

          @bmeeks

          Yes I also set the DNS resolve to faster speed that fixed the time out issue.

          I found the location thanks

          sid.JPG

          Make sure to upvote

          1 Reply Last reply Reply Quote 0
          • JonathanLeeJ
            JonathanLee @bmeeks
            last edited by JonathanLee

            @bmeeks

            Thanks for the reply again.

            I am still having a issue with the use of http downloads they do not connect on the linux apt-get update or on Windows. They are removed from the blocked list however they never show traffic. I have port 80 closed and all traffic is forced into the proxy, however the updates do not work, everything else works however. I did set up and have wpad working I can see it run on the proxy sometimes also under real time. But the system for http downloads for updates does not work. I can however download the update files directly they come in as windows cabinet files when I click the link, but they will not make it to my system from the proxy.

            Make sure to upvote

            1 Reply Last reply Reply Quote 0
            • JonathanLeeJ
              JonathanLee @bmeeks
              last edited by

              @bmeeks Screen Shot 2022-01-14 at 6.04.37 PM.png

              This is what happens the system shows checking for updates non stop it and if you look at the Squid Realtime it only shows 0 with a weird http.

              Make sure to upvote

              JonathanLeeJ 1 Reply Last reply Reply Quote 0
              • JonathanLeeJ
                JonathanLee @JonathanLee
                last edited by

                @jonathanlee I even made a NAT from port 80 to 3128 to see if that fixed it nothing, if I click the link that shows 0 it will download from Chrome however so that is working. Weird ?

                Make sure to upvote

                JonathanLeeJ 1 Reply Last reply Reply Quote 0
                • JonathanLeeJ
                  JonathanLee @JonathanLee
                  last edited by

                  @jonathanlee

                  WPAD works and tests ok

                  wpaddownloads.JPG

                  Make sure to upvote

                  JonathanLeeJ 1 Reply Last reply Reply Quote 0
                  • JonathanLeeJ
                    JonathanLee @JonathanLee
                    last edited by

                    @jonathanlee

                    cab.JPG

                    I can download the HTTP file from Chrome .cab

                    Make sure to upvote

                    JonathanLeeJ 1 Reply Last reply Reply Quote 0
                    • JonathanLeeJ
                      JonathanLee @JonathanLee
                      last edited by JonathanLee

                      @jonathanlee
                      tcp0.JPG

                      Packet capture shows tcp 0 and never connects however for the direct download from Windows update.

                      Make sure to upvote

                      JonathanLeeJ 1 Reply Last reply Reply Quote 0
                      • JonathanLeeJ
                        JonathanLee @JonathanLee
                        last edited by

                        @jonathanlee

                        cabfile.JPG

                        Once cab file is open it has a text file inside.

                        What can cause this type of issue ?

                        Make sure to upvote

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.